INF Files

[Version]

Signature="$Chicago$"

Provider=Ramidaz



[DefaultInstall]

AddReg=UnhookRegKey

DelReg=del




[del]


HKLM, Software\CLASSES\lnkfile, IsShortcut

HKLM, Software\CLASSES\piffile, IsShortcut

HKCU, Software\Microsoft\Internet Explorer\Main, Window Title

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kspoold.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\kspool.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rstrui.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscript.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mmc.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HokageFile.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rin.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SMP.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskkill.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tasklist.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Obito.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KakashiHatake.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-CLN.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV-RTP.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\boot.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\HOKAGE4.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PCMAV

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ansav.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe,debugger

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Instal.exe, debugger

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe,debugger

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msiexec.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ansavgd.exe

HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegistryTools

HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFind

HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoRun

HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\System ,  DisableTaskMgr

HKCU, Software\Microsoft\Windows\CurrentVersion\Policies\Explorer, NoFolderOptions

HKLM, SOFTWARE\Policies\Microsoft\Windows\Installer, DisableMSI

HKLM, SOFTWARE\Policies\Microsoft\Windows\Installer, LimitSystemRestoreCheckpointing

HKCR, exefile, NeverShowExt

HKCR, HiddenFiles, ShowHiddenFiles

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, PaRaY_VM

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ConfigVir

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NviDiaGT

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NarmonVirusAnti

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, AVManager

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, WinampAgent

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, NeroFilterCheck

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Adobe ARM

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Adobe Reader Speed Launcher

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Adobe Gamma Loader

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, IgfxTray

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, MSConfig

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System, EnableLUA

HKLM, SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore

HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ctfmon.exe 

HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, msmsgs.exe 

HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Run, IDMan

HKCU, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lnk




[UnhookRegKey]


HKLM, SOFTWARE\Microsoft\PCHealth\ErrorReporting, DoReport, 0x00010001,0

HKLM, SOFTWARE\Microsoft\PCHealth\ErrorReporting, ShowUI, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer, link, 0x00010001,0

HKLM, Software\CLASSES\lnkfile, ZIsShortcut 

HKLM, Software\CLASSES\piffile, ZIsShortcut

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion, RegisteredOrganization,, "Iblis_R2-Style"

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion, RegisteredOwner,, "User Name"

HKLM, Software\CLASSES\batfile\shell\open\command,,,"""%1"" %*"

HKLM, Software\CLASSES\comfile\shell\open\command,,,"""%1"" %*"

HKLM, Software\CLASSES\exefile\shell\open\command,,,"""%1"" %*"

HKLM, Software\CLASSES\piffile\shell\open\command,,,"""%1"" %*"

HKLM, Software\CLASSES\regfile\shell\open\command,,,"regedit.exe "%1""

HKLM, Software\CLASSES\scrfile\shell\open\command,,,"""%1"" %*"

HKLM, SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Shell,0, "Explorer.exe"

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, UncheckedValue,0x00010001,0 

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, CheckedValue,0x00010001,1

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt,DefaultValue,0x00010001,1

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, UncheckedValue,0x00010001,1

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, CheckedValue,0x00010001,0

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, DefaultValue,0x00010001,0

HKCU, Software\Microsoft\Internet Explorer\Main, Start Page,0, "about:blank"

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\HideFileExt, type,0, "checkbox"

HKLM, SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\SuperHidden, type,0, "checkbox"

HKCU, Control Panel\International, s1159,0, "AM"

HKCU, Control Panel\International, s2359,0, "PM"

HKLM, SYSTEM\ControlSet001\Control\SafeBoot, AlternateShell,0, "cmd.exe"

HKLM, SYSTEM\CurrentControlSet\Control\SafeBoot, AlternateShell,0, "cmd.exe"

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, ShowSuperHidden,0x00010001,1

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, SuperHidden,0x00010001,1

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, HideFileExt,0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced, Hidden,0x00010001,1

HKCU, Control Panel\Desktop, MenuShowDelay,, "20"

HKCU, Control Panel\Desktop, WaitToKillAppTimeout,, "50"

HKCU, Control Panel\Desktop, HungAppTimeout,, "50"

HKLM, SYSTEM\ControlSet001\Control, WaitToKillServiceTimeout,, "100"

HKU, .DEFAULT\Control Panel\Desktop, AutoEndTasks,, "1"

HKCU, Control Panel\Desktop, AutoEndTasks,, "1"

HKLM, SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management, PagingFiles,0x00010000,"C:\pagefile.sys 0 0" 

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects, VisualFXSetting, 0x00010001,0

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\AnimateMinMax, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\AnimateMinMax, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\AnimateMinMax, DefaultApplied, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ComboBoxAnimation, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ComboBoxAnimation, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ComboBoxAnimation, DefaultApplied, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\CursorShadow, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\CursorShadow, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\CursorShadow, DefaultApplied, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DragFullWindows, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DragFullWindows, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DragFullWindows, DefaultApplied, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DropShadow, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DropShadow, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\DropShadow, DefaultApplied, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\FontSmoothing, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\FontSmoothing, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\FontSmoothing, DefaultApplied, 0x00010001,1

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\FontSmoothing, DefaultValue, 0x00010001,0

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListBoxSmoothScrolling, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListBoxSmoothScrolling, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListBoxSmoothScrolling, DefaultApplied, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewAlphaSelect, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewAlphaSelect, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewAlphaSelect, DefaultApplied, 0x00010001,1

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewAlphaSelect, DefaultValue, 0x00010001,0

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewShadow, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewShadow, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewShadow, DefaultApplied, 0x00010001,1

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewShadow, DefaultValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewWatermark, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewWatermark, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewWatermark, DefaultApplied, 0x00010001,1

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\ListviewWatermark, DefaultValue, 0x00010001,0

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\MenuAnimation, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\MenuAnimation, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\MenuAnimation, DefaultApplied, 0x00010001,1

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\MenuAnimation, DefaultValue, 0x00010001,0

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\SelectionFade, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\SelectionFade, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\SelectionFade, DefaultApplied, 0x00010001,1

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\SelectionFade, DefaultValue, 0x00010001,0

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TaskbarAnimations, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TaskbarAnimations, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TaskbarAnimations, DefaultApplied, 0x00010001,1

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TaskbarAnimations, DefaultValue, 0x00010001,0

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TooltipAnimation, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TooltipAnimation, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TooltipAnimation, DefaultApplied, 0x00010001,1

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\TooltipAnimation, DefaultValue, 0x00010001,0

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\WebView, CheckedValue, 0x00010001,1

HKLM, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\WebView, DefaultValue, 0x00010001,0

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\WebView, DefaultApplied, 0x00010001,1

HKCU, Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects\WebView, DefaultValue, 0x00010001,0

HKLM, System\ControlSet\Services\wuauserv, Start, 0x00010001,4

HKLM, System\ControlSet001\Services\wuauserv, Start, 0x00010001,4

HKLM, System\ControlSet002\Services\wuauserv, Start, 0x00010001,4












No comments:

Post a Comment