[Version]
Signature="$Chicago$"
Provider=Ramidaz
[DefaultInstall]
AddReg=UnhookRegKey
DelReg=del
[del]
HKLM, Software\CLASSES\lnkfile, IsShortcut
HKLM, Software\CLASSES\piffile, IsShortcut
HKCU, Software\Microsoft\Internet Explorer\Main, Window Title
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kspoold.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kspool.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscript.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmc.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HokageFile.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rin.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SMP.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskkill.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tasklist.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Obito.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KakashiHatake.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-CLN.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-RTP.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\boot.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HOKAGE4.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ansav.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe,debugger
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Instal.exe, debugger
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe,debugger
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ansavgd.exe
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFind
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoRun
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System , DisableTaskMgr
HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions
HKLM, SOFTWARE\Policies\Microsoft\Windows\Installer, DisableMSI
HKLM, SOFTWARE\Policies\Microsoft\Windows\Installer, LimitSystemRestoreCheckpointing
HKCR, exefile, NeverShowExt
HKCR, HiddenFiles, ShowHiddenFiles
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, PaRaY_VM
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ConfigVir
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NviDiaGT
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NarmonVirusAnti
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, AVManager
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, WinampAgent
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NeroFilterCheck
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Adobe ARM
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Adobe Reader Speed Launcher
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Adobe Gamma Loader
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, IgfxTray
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSConfig
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System, EnableLUA
HKLM, SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore
HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ctfmon.exe
HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, msmsgs.exe
HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, IDMan
HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lnk
[UnhookRegKey]
HKLM, SOFTWARE\Microsoft\PCHealth\ErrorReporting, DoReport, 0x00010001,0
HKLM, SOFTWARE\Microsoft\PCHealth\ErrorReporting, ShowUI, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer, link, 0x00010001,0
HKLM, Software\CLASSES\lnkfile, ZIsShortcut
HKLM, Software\CLASSES\piffile, ZIsShortcut
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion, RegisteredOrganization,, "Iblis_R2-Style"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion, RegisteredOwner,, "User Name"
HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"
HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""
HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"
HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, UncheckedValue,0x00010001,0
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, CheckedValue,0x00010001,1
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt,DefaultValue,0x00010001,1
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, UncheckedValue,0x00010001,1
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, CheckedValue,0x00010001,0
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, DefaultValue,0x00010001,0
HKCU, Software\Microsoft\Internet Explorer\Main, Start Page,0, "about:blank"
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, type,0, "checkbox"
HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, type,0, "checkbox"
HKCU, Control Panel\International, s1159,0, "AM"
HKCU, Control Panel\International, s2359,0, "PM"
HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, "cmd.exe"
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, ShowSuperHidden,0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, SuperHidden,0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, HideFileExt,0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, Hidden,0x00010001,1
HKCU, Control Panel\Desktop, MenuShowDelay,, "20"
HKCU, Control Panel\Desktop, WaitToKillAppTimeout,, "50"
HKCU, Control Panel\Desktop, HungAppTimeout,, "50"
HKLM, SYSTEM\ControlSet001\Control, WaitToKillServiceTimeout,, "100"
HKU, .DEFAULT\Control Panel\Desktop, AutoEndTasks,, "1"
HKCU, Control Panel\Desktop, AutoEndTasks,, "1"
HKLM, SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management, PagingFiles,0x00010000,"C:\pagefile.sys 0 0"
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects, VisualFXSetting, 0x00010001,0
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\AnimateMinMax, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\AnimateMinMax, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\AnimateMinMax, DefaultApplied, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ComboBoxAnimation, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ComboBoxAnimation, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ComboBoxAnimation, DefaultApplied, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\CursorShadow, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\CursorShadow, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\CursorShadow, DefaultApplied, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DragFullWindows, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DragFullWindows, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DragFullWindows, DefaultApplied, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DropShadow, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DropShadow, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DropShadow, DefaultApplied, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\FontSmoothing, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\FontSmoothing, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\FontSmoothing, DefaultApplied, 0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\FontSmoothing, DefaultValue, 0x00010001,0
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListBoxSmoothScrolling, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListBoxSmoothScrolling, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListBoxSmoothScrolling, DefaultApplied, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewAlphaSelect, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewAlphaSelect, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewAlphaSelect, DefaultApplied, 0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewAlphaSelect, DefaultValue, 0x00010001,0
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewShadow, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewShadow, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewShadow, DefaultApplied, 0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewShadow, DefaultValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewWatermark, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewWatermark, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewWatermark, DefaultApplied, 0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewWatermark, DefaultValue, 0x00010001,0
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\MenuAnimation, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\MenuAnimation, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\MenuAnimation, DefaultApplied, 0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\MenuAnimation, DefaultValue, 0x00010001,0
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\SelectionFade, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\SelectionFade, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\SelectionFade, DefaultApplied, 0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\SelectionFade, DefaultValue, 0x00010001,0
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TaskbarAnimations, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TaskbarAnimations, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TaskbarAnimations, DefaultApplied, 0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TaskbarAnimations, DefaultValue, 0x00010001,0
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TooltipAnimation, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TooltipAnimation, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TooltipAnimation, DefaultApplied, 0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TooltipAnimation, DefaultValue, 0x00010001,0
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\WebView, CheckedValue, 0x00010001,1
HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\WebView, DefaultValue, 0x00010001,0
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\WebView, DefaultApplied, 0x00010001,1
HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\WebView, DefaultValue, 0x00010001,0
HKLM, System\ControlSet\Services\wuauserv, Start, 0x00010001,4
HKLM, System\ControlSet001\Services\wuauserv, Start, 0x00010001,4
HKLM, System\ControlSet002\Services\wuauserv, Start, 0x00010001,4
No comments:
Post a Comment