ciao luke grazie al tuo prezioso aiuto penso di essere riuscito a fare qualcosa..... ora però ho acceso anche i due hard disk esterni e facendo un scan on line con bitdefender mi ha trovato questo e no riesco a capire se gli ha rimossi o no...............ti posto come mi hai chiesto anche il report di systemscan e anche questa volta e non so se è importante ho dovuto togliere il segno di spunta a HIDDEN OBIECTS perchè altrimenti il pc mi va in crash...........grazie grazie grazie
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)=>keygen.exe
Infected with: Trojan.Downloader.Small.BHH
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)=>keygen.exe
Infected with: Trojan.Downloader.Small.BHH
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)=>keygen.exe
Disinfection failed
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)=>keygen.exe
Disinfection failed
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)=>keygen.exe
Deleted
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)=>keygen.exe
Deleted
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)
Update failed
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)
Update failed
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)=>crack.exe
Infected with: Trojan.Peed.Gen
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)=>crack.exe
Infected with: Trojan.Peed.Gen
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)=>crack.exe
Disinfection failed
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)=>crack.exe
Disinfection failed
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)=>crack.exe
Deleted
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)=>crack.exe
Deleted
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)
Update failed
G:\System Volume Information\_restore{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}\RP350\A0076482.exe=>(RAR Sfx o)
Update failed
SystemScan -
http://www.suspectfile.com - ver. 3.1.1
Running on: Windows XP PROFESSIONAL Edition, Service Pack 2 (2600.5.1)
System directory: C:\WINDOWS
Date: 06/06/2007
Time: 22.15.35
Output limited to:
-Recent files
-PC accounts
-Registry Run Keys
-Autoplay settings (autorun.inf)
-Scheduled jobs
-Running Services
-Duplicates in BAK folders
-Device Driver Services
-Svchost.exe instances
-Network settings
-Include HOSTS file
-Loaded Dlls
-Alternate Data Sreams
-Encrypted Files
-Suspicious Files
-Include hijackthis.log
-Installed Applications
===================== Accounts on this PC =====================
Users on this computer:
Is Admin? | Username
------------------
Yes | Administrator
| ASPNET
| Guest (Disabled)
| HelpAssistant (Disabled)
Yes | Max
| SUPPORT_388945a0 (Disabled)
### users folders
16/06/2006 22.39.25 (DIR) 0 byte 355 days old -- Default User
21/06/2006 19.43.29 (DIR) 0 byte 350 days old -- All Users
29/01/2007 18.11.12 (DIR) 0 byte 128 days old -- NetworkService
29/01/2007 18.11.12 (DIR) 0 byte 128 days old -- LocalService
06/06/2007 22.01.19 (DIR) 0 byte 0 days old -- Max
===================== Recent files (60 days old)=====================
----- recent files in C:\
06/05/2007 15.25.25 (DIR) 0 byte 31 days old -- Temp
04/06/2007 16.37.39 (DIR) 0 byte 2 days old -- Documents and Settings
04/06/2007 16.44.20 (DIR) 0 byte 2 days old -- Config.Msi
04/06/2007 16.47.24 (DIR) 0 byte 2 days old -- Programmi
04/06/2007 18.56.50 (DIR) 0 byte 2 days old -- System Volume Information
05/06/2007 18.28.16 7042 byte 1 days old -- VundoFix.txt
05/06/2007 18.43.55 (DIR) 0 byte 1 days old -- Program Files
05/06/2007 18.44.37 12928 byte 1 days old -- avenger 2.txt
05/06/2007 18.51.06 22552 byte 1 days old -- avenger.txt
05/06/2007 18.51.26 22554 byte 1 days old -- avenger 3.txt
06/06/2007 14.32.47 (DIR) 0 byte 0 days old -- Media
06/06/2007 16.42.38 1570 byte 0 days old -- rapport.txt
06/06/2007 16.51.04 211 byte 0 days old -- boot.ini
06/06/2007 20.16.35 (DIR) 0 byte 0 days old -- VundoFix Backups
06/06/2007 20.16.46 (DIR) 0 byte 0 days old -- avenger
06/06/2007 22.14.17 1610612736 byte 0 days old -- pagefile.sys
06/06/2007 22.14.20 (DIR)1073074176 byte 0 days old -- hiberfil.sys
06/06/2007 22.14.43 (DIR) 0 byte 0 days old -- WINDOWS
06/06/2007 22.15.35 (DIR) 0 byte 0 days old -- suspectfile
----- recent files in C:\WINDOWS\
08/04/2007 15.36.23 (DIR) 0 byte 59 days old -- Fonts
08/04/2007 15.58.39 (DIR) 0 byte 59 days old -- Minidump
08/04/2007 16.36.40 771 byte 59 days old -- ULEAD32.INI
11/04/2007 15.30.20 (DIR) 0 byte 56 days old -- $NtUninstallKB932168$
11/04/2007 15.30.29 (DIR) 0 byte 56 days old -- $NtUninstallKB930178$
11/04/2007 15.30.34 (DIR) 0 byte 56 days old -- $NtUninstallKB931261$
11/04/2007 15.30.40 (DIR) 0 byte 56 days old -- $NtUninstallKB931784$
11/04/2007 16.00.48 (DIR) 0 byte 56 days old -- msagent
24/04/2007 17.46.53 (DIR) 0 byte 43 days old -- pss
09/05/2007 15.33.21 (DIR) 0 byte 28 days old -- $NtUninstallKB930916$
09/05/2007 15.33.41 (DIR) 0 byte 28 days old -- ie7updates
10/05/2007 19.14.39 (DIR) 0 byte 27 days old -- Debug
25/05/2007 20.42.41 (DIR) 0 byte 12 days old -- $hf_mig$
25/05/2007 20.42.44 (DIR) 0 byte 12 days old -- $NtUninstallKB927891$
03/06/2007 21.17.45 (DIR) 0 byte 3 days old -- Downloaded Program Files
04/06/2007 16.44.12 (DIR) 0 byte 2 days old -- Installer
04/06/2007 19.42.31 131168 byte 2 days old -- urrppp.dll
05/06/2007 15.15.51 1060810 byte 1 days old -- ppprru.ini
05/06/2007 15.19.39 143 byte 1 days old -- mcrh.tmp
06/06/2007 14.32.38 (DIR) 0 byte 0 days old -- Media
06/06/2007 14.34.14 317 byte 0 days old -- SBWIN.INI
06/06/2007 16.04.45 (DIR) 0 byte 0 days old -- Prefetch
06/06/2007 16.51.04 277 byte 0 days old -- system.ini
06/06/2007 16.51.04 507 byte 0 days old -- win.ini
06/06/2007 16.52.45 0 byte 0 days old -- Sti_Trace.log
06/06/2007 17.05.59 (DIR) 0 byte 0 days old -- inf
06/06/2007 17.06.09 (DIR) 0 byte 0 days old -- Help
06/06/2007 17.06.13 (DIR) 0 byte 0 days old -- SoftwareDistribution
06/06/2007 17.17.17 229 byte 0 days old -- NeroDigital.ini
06/06/2007 20.17.39 (DIR) 0 byte 0 days old -- BDOSCAN8
06/06/2007 22.14.17 (DIR) 0 byte 0 days old -- system32
06/06/2007 22.14.17 0 byte 0 days old -- MEMORY.DMP
06/06/2007 22.14.22 2048 byte 0 days old -- bootstat.dat
06/06/2007 22.14.23 (DIR) 0 byte 0 days old -- CSC
06/06/2007 22.14.25 740 byte 0 days old -- SchedLgU.Txt
06/06/2007 22.14.29 3206968 byte 0 days old -- {00000002-00000000-00000009-00001102-00000004-00521102}.CDF
06/06/2007 22.14.35 50 byte 0 days old -- wiaservc.log
06/06/2007 22.14.37 38829 byte 0 days old -- WindowsUpdate.log
06/06/2007 22.14.37 159 byte 0 days old -- wiadebug.log
06/06/2007 22.14.43 0 byte 0 days old -- 0.log
06/06/2007 22.14.52 (DIR) 0 byte 0 days old -- TEMP
----- recent files in C:\WINDOWS\Downloaded Program Files\
----- recent files in C:\WINDOWS\system\
----- recent files in C:\WINDOWS\system32\
08/04/2007 15.54.04 258248 byte 59 days old -- FNTCACHE.DAT
09/04/2007 11.25.04 444928 byte 58 days old -- CTAPO32.dll
09/04/2007 11.25.26 45568 byte 58 days old -- ctppld.dll
09/04/2007 11.25.36 48400 byte 58 days old -- AddCat.exe
09/04/2007 12.19.02 48640 byte 58 days old -- devreg.dll
09/04/2007 12.19.18 5120 byte 58 days old -- enlocstr.exe
09/04/2007 12.19.44 274587 byte 58 days old -- ctsbas2w.dat
09/04/2007 12.22.04 50176 byte 58 days old -- ctedasio.dll
09/04/2007 12.22.04 205312 byte 58 days old -- ct_oal.dll
09/04/2007 12.24.30 46273 byte 58 days old -- ctdnlstr.dat
09/04/2007 12.29.28 934400 byte 58 days old -- CTxfispi.exe
09/04/2007 12.29.30 10752 byte 58 days old -- Ct20xspi.dll
09/04/2007 12.29.30 43520 byte 58 days old -- Ctxfireg.exe
09/04/2007 12.32.20 10240 byte 58 days old -- ctdcres.dll
09/04/2007 12.32.20 227840 byte 58 days old -- ctdc0000.dll
09/04/2007 12.32.22 335872 byte 58 days old -- ctdc0001.dll
09/04/2007 12.32.22 131072 byte 58 days old -- ctdcifce.dll
09/04/2007 12.32.22 78336 byte 58 days old -- ctscal.dll
09/04/2007 12.32.24 69632 byte 58 days old -- ctthxcal.dll
09/04/2007 12.32.24 9216 byte 58 days old -- ctpres.dll
09/04/2007 12.32.28 12800 byte 58 days old -- ctmmep.dll
09/04/2007 12.32.30 56832 byte 58 days old -- CTpcmcia.dll
09/04/2007 12.32.32 19968 byte 58 days old -- Ctxfihlp.exe
09/04/2007 12.32.32 37888 byte 58 days old -- psconv.exe
09/04/2007 12.32.34 46592 byte 58 days old -- CTxfiSpk.dll
09/04/2007 12.32.34 35840 byte 58 days old -- CTxfiBtn.dll
09/04/2007 12.32.36 38400 byte 58 days old -- readreg.exe
09/04/2007 12.33.36 86016 byte 58 days old -- ctcoinst.dll
09/04/2007 12.33.36 163328 byte 58 days old -- ctdvinst.dll
09/04/2007 12.33.38 11776 byte 58 days old -- inres.dll
09/04/2007 12.33.50 43520 byte 58 days old -- CTBurst.dll
09/04/2007 12.55.14 97785 byte 58 days old -- instwdm.ini
10/04/2007 06.11.58 8009 byte 57 days old -- CTAPO32.UDA
11/04/2007 21.33.20 83248 byte 56 days old -- SilSupp.cpl
12/04/2007 08.10.16 546048 byte 55 days old -- CTAUDFX.DLL
12/04/2007 08.10.18 168192 byte 55 days old -- CTEAPSFX.DLL
12/04/2007 08.10.20 280320 byte 55 days old -- CTEDSPFX.DLL
12/04/2007 08.10.20 94976 byte 55 days old -- CTERFXFX.DLL
12/04/2007 08.10.22 323328 byte 55 days old -- CTEDSPSY.DLL
12/04/2007 08.10.22 128768 byte 55 days old -- CTEDSPIO.DLL
12/04/2007 08.10.24 1317632 byte 55 days old -- CTEXFIFX.DLL
12/04/2007 08.10.26 66816 byte 55 days old -- CTHWIUT.DLL
12/04/2007 08.10.26 164608 byte 55 days old -- CT20XUT.DLL
12/04/2007 08.10.28 105728 byte 55 days old -- APOMgrH.dll
16/04/2007 22.45.12 38232 byte 51 days old -- wucltui.dll.mui
16/04/2007 22.45.20 53080 byte 51 days old -- wuauclt.exe
16/04/2007 22.45.20 43352 byte 51 days old -- wups2.dll
16/04/2007 22.45.28 92504 byte 51 days old -- cdm.dll
16/04/2007 22.45.36 203096 byte 51 days old -- wuweb.dll
16/04/2007 22.45.40 216408 byte 51 days old -- wuaucpl.cpl
16/04/2007 22.45.42 21336 byte 51 days old -- wuaueng.dll.mui
16/04/2007 22.45.42 325976 byte 51 days old -- wucltui.dll
16/04/2007 22.45.48 549720 byte 51 days old -- wuapi.dll
16/04/2007 22.45.54 1710936 byte 51 days old -- wuaueng.dll
16/04/2007 22.47.04 30040 byte 51 days old -- wuapi.dll.mui
16/04/2007 22.47.32 30040 byte 51 days old -- wuaucpl.cpl.mui
16/04/2007 22.47.36 33624 byte 51 days old -- wups.dll
18/04/2007 18.14.23 2854400 byte 49 days old -- msi.dll
27/04/2007 22.45.12 14970328 byte 40 days old -- MRT.exe
30/04/2007 17.35.28 95872 byte 37 days old -- AVASTSS.scr
30/04/2007 17.46.10 745600 byte 37 days old -- aswBoot.exe
01/05/2007 09.29.51 2934 byte 36 days old -- CONFIG.NT
03/06/2007 12.01.19 (DIR) 0 byte 3 days old -- appmgmt
04/06/2007 18.49.00 39124 byte 2 days old -- tmpC0.tmp.dll
04/06/2007 18.53.19 39124 byte 2 days old -- tmpCA.tmp.dll
04/06/2007 19.41.31 39124 byte 2 days old -- tmp4.tmp.dll
05/06/2007 15.31.12 13457536 byte 1 days old -- dn_crash.log
05/06/2007 18.29.15 39124 byte 1 days old -- tmp6.tmp.dll
05/06/2007 18.42.25 77 byte 1 days old -- chcdec.dns
06/06/2007 14.15.47 2228 byte 0 days old -- wpa.dbl
06/06/2007 14.19.47 (DIR) 0 byte 0 days old -- Data
06/06/2007 14.32.58 63016 byte 0 days old -- perfc009.dat
06/06/2007 14.32.58 1001600 byte 0 days old -- PerfStringBackup.INI
06/06/2007 14.32.59 402406 byte 0 days old -- perfh009.dat
06/06/2007 14.32.59 74926 byte 0 days old -- perfc010.dat
06/06/2007 14.32.59 448752 byte 0 days old -- perfh010.dat
06/06/2007 14.35.31 (DIR) 0 byte 0 days old -- drivers
06/06/2007 14.36.33 11564 byte 0 days old -- DVCState-{00000002-00000000-00000009-00001102-00000004-00521102}.rfx
06/06/2007 14.38.03 (DIR) 0 byte 0 days old -- Defaults
06/06/2007 16.42.23 1918 byte 0 days old -- tmp.reg
06/06/2007 16.42.23 0 byte 0 days old -- tmp.txt
06/06/2007 17.01.46 19104 byte 0 days old -- BMXStateBkp-{00000002-00000000-00000009-00001102-00000004-00521102}.rfx
06/06/2007 17.01.46 19104 byte 0 days old -- BMXState-{00000002-00000000-00000009-00001102-00000004-00521102}.rfx
06/06/2007 17.01.46 23472 byte 0 days old -- BMXCtrlState-{00000002-00000000-00000009-00001102-00000004-00521102}.rfx
06/06/2007 17.01.46 23472 byte 0 days old -- BMXBkpCtrlState-{00000002-00000000-00000009-00001102-00000004-00521102}.rfx
06/06/2007 17.01.46 1080 byte 0 days old -- settings.sfm
06/06/2007 17.01.46 1080 byte 0 days old -- settingsbkup.sfm
06/06/2007 17.01.46 24 byte 0 days old -- DVCStateBkp-{00000002-00000000-00000009-00001102-00000004-00521102}.dat
06/06/2007 17.01.46 24 byte 0 days old -- DVCState-{00000002-00000000-00000009-00001102-00000004-00521102}.dat
06/06/2007 22.14.44 (DIR) 0 byte 0 days old -- CatRoot2
06/06/2007 22.14.50 (DIR) 0 byte 0 days old -- dllcache
----- recent files in C:\WINDOWS\system32\drivers\
10/04/2007 04.21.06 347128 byte 57 days old -- ctdvda2k.sys
10/04/2007 04.31.18 163112 byte 57 days old -- haP16v2k.sys
10/04/2007 04.32.06 189736 byte 57 days old -- haP17v2k.sys
10/04/2007 04.32.34 16168 byte 57 days old -- pfmodnt.sys
10/04/2007 06.03.12 1164072 byte 57 days old -- ha20x2k.sys
11/04/2007 21.32.48 110384 byte 56 days old -- SI3114r.sys
11/04/2007 21.32.52 17328 byte 56 days old -- SiWinAcc.sys
30/04/2007 17.37.23 26888 byte 37 days old -- aavmker4.sys
30/04/2007 17.38.51 43176 byte 37 days old -- aswTdi.sys
30/04/2007 17.39.41 23416 byte 37 days old -- aswRdr.sys
30/04/2007 17.41.42 94552 byte 37 days old -- aswmon2.sys
30/04/2007 17.41.55 85952 byte 37 days old -- aswmon.sys
03/06/2007 19.37.14 1400 byte 3 days old -- fwdrv.err
06/06/2007 16.32.15 (DIR) 0 byte 0 days old -- etc
----- recent files in C:\WINDOWS\temp\
06/06/2007 17.03.14 16384 byte 0 days old -- Perflib_Perfdata_674.dat
06/06/2007 22.14.25 (DIR) 0 byte 0 days old -- _avast4_
06/06/2007 22.14.26 16384 byte 0 days old -- Perflib_Perfdata_678.dat
----- recent files in C:\Programmi\
08/04/2007 15.36.21 (DIR) 0 byte 59 days old -- Ulead Systems
09/05/2007 15.33.47 (DIR) 0 byte 28 days old -- Internet Explorer
03/06/2007 09.53.25 (DIR) 0 byte 3 days old -- Spybot - Search & Destroy
03/06/2007 10.14.29 (DIR) 0 byte 3 days old -- Windows Media Connect 2
06/06/2007 14.32.49 (DIR) 0 byte 0 days old -- Creative
06/06/2007 14.35.52 (DIR) 0 byte 0 days old -- InstallShield Installation Information
06/06/2007 21.18.42 (DIR) 0 byte 0 days old -- eMule
----- recent files in C:\Programmi\File comuni\
===================== Duplicates in BAK folders =====================
No BAK folders found
===================== REGISTRY SCAN =====================
-----HKLM\Software\Microsoft\Windows\CurrentVersion\Run-----
[Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe"
"WebCam Go Sti Service Application"="wbcgosvc"
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe"
"CloneCDTray"="\"C:\Programmi\SlySoft\CloneCD\CloneCDTray.exe\" /s"
"CTStartup"="C:\Programmi\Creative\Splash Screen\CTEaxSpl.EXE /run\00\00\00\00\00\00\00hö\12\00å‚Ýs\14÷\12\00”\Àwˆ ¾wÿÿÿÿÎÿwçÿw4\00\00\00°ö\12\00.Ä¿w4\00\00\00\00\00\00\004\00\00\00TAÔs4\00\00\00à\00\01\00l:2\00ü„9~¤…9~à\00\01\00\01\00\00\00\„Ç\00\„Ç\00ôþ\12\00\14÷\12\00U·9~…·9~\„Ç\00\„Ç\00ôþ\12\00Xú`\00ìö\12\00ŒC@\00\„Ç\00\„Ç\00\09ðÙsà\00\01\00\„Ç\00»\11Ôs\„Ç\00P:2\00A\10ÔsP:2\00ŒC@\00xþ\12\00`|Áw\„Ç\00â\13@"
"WINDVDPatch"="CTHELPER.EXE"
[Run\OptionalComponents]
[Run\OptionalComponents\IMAIL]
"Installed"="1"
[Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[Run\OptionalComponents\MSFS]
"Installed"="1"
-----HKCU\Software\Microsoft\Windows\CurrentVersion\Run-----
[Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe\""
"Taskbar"="C:\Programmi\Creative\TaskBar\CTLTask.exe"
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe"
-----HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run-----
[Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE"
-----HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run-----
[run]
-----HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run-----
-----HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows-----
[Windows]
"AppInit_DLLs"=""
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad-----
[ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
#### HKCR\CLSID\{7849596a-48ea-486e-8937-a2a3009f31a9}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
#### HKCR\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
#### HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32 @=expand:"C:\WINDOWS\system32\webcheck.dll"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
#### HKCR\CLSID\{35CEC8A3-2BE6-11D2-8773-92E220524153}\InprocServer32 @="C:\WINDOWS\system32\stobject.dll"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
#### HKCR\CLSID\{AAA288BA-9A4C-45B0-95D7-94D524869DB5}\InprocServer32 @="C:\WINDOWS\system32\WPDShServiceObj.dll"
-----HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks-----
[ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
#### HKCR\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InprocServer32 @="shell32.dll"
"{E5225210-F293-40FE-BB2F-D5A3C7F13C47}"=""
-----HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon-----
[Winlogon]
"Shell"="Explorer.exe"
"System"=""
"Userinit"="C:\WINDOWS\system32\userinit.exe,"
"VmApplet"="rundll32 shell32,Control_RunDLL \"sysdm.cpl\""
"UIHost"=expand:"logonui.exe"
"LogonType"=dword:00000001
"WinStationsDisabled"="0"
[Winlogon\GPExtensions]
[Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}]
"@="Senza fili"
"DllName"=expand:"gptext.dll"
[Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}]
"@="Folder Redirection"
"DllName"=expand:"fdeploy.dll"
[Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
"@="Quota disco Microsoft"
"DllName"=expand:"dskquota.dll"
[Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}]
"@="Utilità di pianificazione pacchetti QoS"
"DllName"=expand:"gptext.dll"
[Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}]
"@="Script"
"DllName"=expand:"gptext.dll"
[Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}]
"@="Internet Explorer Zonemapping"
"DllName"=expand:"iedkcs32.dll"
[Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}]
"DllName"=expand:"scecli.dll"
"@="Security"
[Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}]
"DllName"="iedkcs32.dll"
"@="Internet Explorer Branding"
[Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}]
"DllName"=expand:"scecli.dll"
"@="EFS recovery"
[Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}]
"@="Microsoft Offline Files"
"DllName"=expand:"%SystemRoot%\System32\cscui.dll"
[Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
"@="Installazione software"
"DllName"=expand:"appmgmts.dll"
[Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}]
"@="Protezione IP"
"DllName"=expand:"gptext.dll"
[Winlogon\Notify]
[Winlogon\Notify\AtiExtEvent]
"DLLName"="Ati2evxx.dll"
"Lock"="AtiLockEvent"
"Logoff"="AtiLogoffEvent"
"Logon"="AtiLogonEvent"
"Disconnect"="AtiDisConnectEvent"
"Reconnect"="AtiReConnectEvent"
"Safe"=dword:00000000
"StartScreenSaver"="AtiStartScreenSaverEvent"
"StartShell"="AtiStartShellEvent"
"Startup"="AtiStartupEvent"
"StopScreenSaver"="AtiStopScreenSaverEvent"
"Unlock"="AtiUnLockEvent"
[Winlogon\Notify\crypt32chain]
"DllName"=expand:"crypt32.dll"
"Logoff"="ChainWlxLogoffEvent"
[Winlogon\Notify\cryptnet]
"DllName"=expand:"cryptnet.dll"
"Logoff"="CryptnetWlxLogoffEvent"
[Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"StartShell"="WinlogonStartShellEvent"
[Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
[Winlogon\Notify\Schedule]
"DllName"=expand:"wlnotify.dll"
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"
[Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"DllName"=expand:"sclgntfy.dll"
[Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
[Winlogon\Notify\termsrv]
"DllName"=expand:"wlnotify.dll"
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"
[Winlogon\Notify\WgaLogon]
"Logon"="WLEventLogon"
"Logoff"="WLEventLogoff"
"Startup"="WLEventStartup"
"StartScreenSaver"="WLEventStartScreenSaver"
"StopScreenSaver"="WLEventStopScreenSaver"
"Lock"="WLEventLock"
"Unlock"="WLEventUnlock"
"StartShell"="WLEventStartShell"
"PostShell"="WLEventPostShell"
"Disconnect"="WLEventDisconnect"
"Reconnect"="WLEventReconnect"
"SafeMode"=dword:00000000
"MaxWait"=dword:ffffffff
"DllName"=expand:"WgaLogon.dll"
[Winlogon\Notify\WgaLogon\Settings]
[Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
[Winlogon\SpecialAccounts]
[Winlogon\SpecialAccounts\UserList]
"HelpAssistant"=dword:00000000
"TsInternetUser"=dword:00000000
"SQLAgentCmdExec"=dword:00000000
"NetShowServices"=dword:00000000
"IWAM_"=dword:00010000
"IUSR_"=dword:00010000
"VUSR_"=dword:00010000
-----HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon-----
[Winlogon]
"ParseAutoexec"="1"
"ExcludeProfileDirs"="Impostazioni locali;Temporary Internet Files;Cronologia;Temp"
"BuildNumber"=dword:00000a28
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options-----
[Image File Execution Options\Your Image File Name Here without a path]
"Debugger"="ntsd -d"
-----HKLM\System\CurrentControlSet\Control\Session Manager\-----
[Session Manager]
"BootExecute"=multi:"autocheck autochk *\00\00"
[Session Manager\SubSystems]
"Windows"=expand:"%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16"
-----HKLM\SYSTEM\CurrentControlSet\Control\WOW-----
[WOW]
"cmdline"=expand:"%SystemRoot%\system32\ntvdm.exe"
"wowcmdline"=expand:"%SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386"
-----HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run-----
-----HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce-----
[RunOnce]
-----HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx-----
[RunOnceEx]
-----HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices-----
[RunServices]
-----HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce-----
-----HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce-----
[RunOnce]
[RunOnce\CTStartup]
"CTStartup"="\"C:\Programmi\Creative\Splash Screen\CTEaxSpl.EXE\" /play\00\00\00\00hö\12\00å‚Ýs\14÷\12\00”\Àwˆ ¾wÿÿÿÿÎÿwçÿw4\00\00\00°ö\12\00.Ä¿w4\00\00\00\00\00\00\004\00\00\00TAÔs4\00\00\00à\00\01\00l:2\00ü„9~¤…9~à\00\01\00\01\00\00\00\„Ç\00\„Ç\00ôþ\12\00\14÷\12\00U·9~…·9~\„Ç\00\„Ç\00ôþ\12\00Xú`\00ìö\12\00ŒC@\00\„Ç\00\„Ç\00\09ðÙsà\00\01\00\„Ç\00»\11Ôs\„Ç\00P:2\00A\10ÔsP:2\00ŒC@\00xþ\12\00`|Áw\„Ç\00â\13@"
-----HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx-----
-----HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices-----
-----HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run-----
-----HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce-----
-----HKLM\Software\Microsoft\Command Processor\Autorun-----
-----HKCU\Software\Microsoft\Command Processor\Autorun-----
-----HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load-----
-----HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup-----
-----HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon-----
-----HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logon-----
-----HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Runonce-----
-----HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Run-----
-----HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms-----
-----HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Runonce-----
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler-----
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Precaricatore Browseui"
#### HKCR\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InprocServer32 @=expand:"%SystemRoot%\system32\Browseui.dll"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Daemon di cache delle categorie di componenti"
#### HKCR\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InprocServer32 @=expand:"%SystemRoot%\system32\Browseui.dll"
-----HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects-----
[Browser Helper Objects]
[Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
@=""
[Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
#### HKCR\CLSID\{53707962-6F74-2D53-2644-206D7942484F}\InprocServer32 @="C:\PROGRA~1\SPYBOT~1\SDHelper.dll"
[Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
@=""
-----HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks-----
[URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
#### HKCR\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\InprocServer32 @="C:\WINDOWS\system32\ieframe.dll"
-----HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder-----
[startupfolder]
[startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Adobe Acrobat Speed Launcher.lnk]
"path"="C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Adobe Acrobat Speed Launcher.lnk"
"backup"="C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe "
"item"="Adobe Acrobat Speed Launcher"
[startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^EPSON Status Monitor 3 Environment Check.lnk]
"path"="C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\EPSON Status Monitor 3 Environment Check.lnk"
"backup"="C:\WINDOWS\pss\EPSON Status Monitor 3 Environment Check.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE "
"item"="EPSON Status Monitor 3 Environment Check"
[startupfolder\C:^Documents and Settings^All Users^Menu Avvio^Programmi^Esecuzione automatica^Ulead Photo Express SE Calendar Checker.lnk]
"path"="C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\Ulead Photo Express SE Calendar Checker.lnk"
"backup"="C:\WINDOWS\pss\Ulead Photo Express SE Calendar Checker.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\PROGRA~1\ULEADS~1\ULEADP~1.0SE\CalCheck.exe "
"item"="Ulead Photo Express SE Calendar Checker"
-----HKCU\Control Panel\Desktop\-----
[Desktop]
[Desktop\WindowMetrics]
-----HKEY_CLASSES_ROOT\exefile\shell\open\command-----
[command]
@="\"%1\" %*"
-----HKEY_CLASSES_ROOT\comfile\shell\open\command-----
[command]
@="\"%1\" %*"
-----HKEY_CLASSES_ROOT\batfile\shell\open\command-----
[command]
@="\"%1\" %*"
-----HKEY_CLASSES_ROOT\piffile\shell\open\command-----
[command]
@="\"%1\" %*"
-----HKEY_CLASSES_ROOT\scrFile\shell\open\command-----
[command]
@="\"%1\" /S"
-----HKEY_CLASSES_ROOT\htafile\shell\open\command-----
[Command]
@="C:\WINDOWS\system32\mshta.exe \"%1\" %*"
-----HKEY_CLASSES_ROOT\logfile\shell\open\command-----
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL-----
[URL]
[URL\DefaultPrefix]
@="http://"
[URL\Prefixes]
"ftp"="ftp://"
"gopher"="gopher://"
"home"="http://"
"mosaic"="http://"
"www"="http://"
-----HKLM\SYSTEM\CurrentControlSet\Control\Lsa-----
[Lsa]
"Authentication Packages"=multi:"msv1_0\00\00"
"Bounds"=hex:00,30,00,00,00,20,00,00
"Security Packages"=multi:"kerberos\00msv1_0\00schannel\00wdigest\00\00"
"ImpersonatePrivilegeUpgradeToolHasRun"=dword:00000001
"LsaPid"=dword:000003c8
"SecureBoot"=dword:00000001
"auditbaseobjects"=dword:00000000
"crashonauditfail"=dword:00000000
"disabledomaincreds"=dword:00000000
"everyoneincludesanonymous"=dword:00000000
"fipsalgorithmpolicy"=dword:00000000
"forceguest"=dword:00000001
"fullprivilegeauditing"=hex:00
"limitblankpassworduse"=dword:00000001
"lmcompatibilitylevel"=dword:00000000
"nodefaultadminowner"=dword:00000001
"nolmhash"=dword:00000000
"restrictanonymous"=dword:00000000
"restrictanonymoussam"=dword:00000001
"Notification Packages"=multi:"scecli\00\00"
[Lsa\AccessProviders]
"ProviderOrder"=multi:"Windows NT Access Provider\00\00"
[Lsa\AccessProviders\Windows NT Access Provider]
"ProviderPath"=expand:"%SystemRoot%\system32\ntmarta.dll"
[Lsa\Audit]
[Lsa\Audit\PerUserAuditing]
[Lsa\Audit\PerUserAuditing\System]
[Lsa\Data]
@Class="61be8f47"
"Pattern"=hex:e9,25,81,e8,07,1c,38,7c,c2,c8,ac,5c,c5,95,a5,57,36,31,62,65,38,\
66,34,37,00,fd,07,00,de,f9,00,00,34,fa,07,00,56,82,47,75,20,fa,07,00,40,fd,\
07,00,4c,fd,07,00,4d,5c,04,ce,3b,51,be,b4,93,ff,d6,61
[Lsa\GBG]
@Class="4d51473b"
"GrafBlumGroup"=hex:da,db,74,ff,3c,a7,b0,b5,66
[Lsa\JD]
@Class="93d6ceb4"
"Lookup"=hex:5f,65,b3,42,c9,dc
[Lsa\Kerberos]
[Lsa\Kerberos\Domains]
[Lsa\Kerberos\SidCache]
[Lsa\MSV1_0]
"Auth132"="iissuba"
"ntlmminclientsec"=dword:00000000
"ntlmminserversec"=dword:00000000
[Lsa\Skew1]
@Class="045cff3f"
"SkewMatrix"=hex:08,11,3f,44,6b,5e,b0,04,fb,cb,8f,9d,2a,ef,07,1a
[Lsa\SSO]
[Lsa\SSO\Passport1.4]
"SSOURL"="http://www.passport.com"
[Lsa\SspiCache]
"Time"=hex:44,7b,ac,99,1d,92,c6,01
[Lsa\SspiCache\digest.dll]
"Name"="Digest"
"Comment"="Digest SSPI Authentication Package"
"Capabilities"=dword:00004050
"RpcId"=dword:0000ffff
"Version"=dword:00000001
"TokenSize"=dword:0000ffff
"Time"=hex:00,e6,db,e6,f1,85,c4,01
"Type"=dword:00000031
[Lsa\SspiCache\msapsspc.dll]
"Name"="DPA"
"Comment"="DPA Security Package"
"Capabilities"=dword:00000037
"RpcId"=dword:00000011
"Version"=dword:00000001
"TokenSize"=dword:00000300
"Time"=hex:00,c7,d1,ec,f1,85,c4,01
"Type"=dword:00000031
[Lsa\SspiCache\msnsspc.dll]
"Name"="MSN"
"Comment"="MSN Security Package"
"Capabilities"=dword:00000037
"RpcId"=dword:00000012
"Version"=dword:00000001
"TokenSize"=dword:00000300
"Time"=hex:00,c7,d1,ec,f1,85,c4,01
"Type"=dword:00000031
-----HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess-----
[SharedAccess]
"DependOnGroup"=multi:"\00"
"DependOnService"=multi:"Netman\00WinMgmt\00\00"
"Description"="Fornisce servizi di conversione indirizzi di rete, indirizzamento e risoluzione nomi e/o servizi di prevenzione intrusione per una rete domestica o una piccola rete aziendale."
"DisplayName"="Windows Firewall / Condivisione connessione Internet (ICS)"
"ErrorControl"=dword:00000001
"ImagePath"=expand:"%SystemRoot%\system32\svchost.exe -k netsvcs"
"ObjectName"="LocalSystem"
"Start"=dword:00000002
"Type"=dword:00000020
[SharedAccess\Epoch]
"Epoch"=dword:0000138b
[SharedAccess\Parameters]
"ServiceDll"=expand:"%SystemRoot%\System32\ipnathlp.dll"
[SharedAccess\Parameters\FirewallPolicy]
[SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications]
[SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Programmi\MSN Messenger\msnmsgr.exe"="C:\Programmi\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Programmi\MSN Messenger\livecall.exe"="C:\Programmi\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts]
[SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008"
[SharedAccess\Parameters\FirewallPolicy\DomainProfile\IcmpSettings]
"AllowInboundEchoRequest"=dword:00000001
[SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=dword:00000001
"DisableNotifications"=dword:00000000
"DoNotAllowExceptions"=dword:00000000
[SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Programmi\Messenger\msmsgs.exe"="C:\Programmi\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Programmi\MSN Messenger\msnmsgr.exe"="C:\Programmi\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Programmi\MSN Messenger\livecall.exe"="C:\Programmi\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\DOCUME~1\Max\IMPOST~1\Temp\win13.tmp.exe"="C:\DOCUME~1\Max\IMPOST~1\Temp\win13.tmp.exe:*:Enabled:win13.tmp"
"C:\WINDOWS\TEMP\winBE.tmp.exe"="C:\WINDOWS\TEMP\winBE.tmp.exe:*:Enabled:winBE.tmp"
"C:\Programmi\NetMeeting\conf.exe"="C:\Programmi\NetMeeting\conf.exe:*:Enabled:Windows® NetMeeting®"
"C:\Programmi\eMule\emule.exe"="C:\Programmi\eMule\emule.exe:*:Enabled:eMule"
[SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
[SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP"="1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007"
"2869:TCP"="2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008"
[SharedAccess\Parameters\FirewallPolicy\StandardProfile\IcmpSettings]
"AllowInboundEchoRequest"=dword:00000001
[SharedAccess\Setup]
"ServiceUpgrade"=dword:00000001
[SharedAccess\Setup\InterfacesUnfirewalledAtUpdate]
"All"=dword:00000001
-----HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Firewall\-----
-----HKEY_LOCAL_MACHINE\SOFTWARE\Winsock2-----
-----HKLM\Software\Microsoft\Ole-----
[Ole]
"DefaultLaunchPermission"=hex:01,00,04,80,5c,00,00,00,6c,00,00,00,00,00,00,00,\
14,00,00,00,02,00,48,00,03,00,00,00,00,00,18,00,1f,00,00,00,01,02,00,00,00,\
00,00,05,20,00,00,00,20,02,00,00,00,00,14,00,0b,00,00,00,01,01,00,00,00,00,\
00,05,04,00,00,00,00,00,14,00,0b,00,00,00,01,01,00,00,00,00,00,05,12,00,00,\
00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,00,05,\
20,00,00,00,20,02,00,00
"MachineLaunchRestriction"=hex:01,00,04,80,48,00,00,00,58,00,00,00,00,00,00,00,\
14,00,00,00,02,00,34,00,02,00,00,00,00,00,18,00,1f,00,00,00,01,02,00,00,00,\
00,00,05,20,00,00,00,20,02,00,00,00,00,14,00,0b,00,00,00,01,01,00,00,00,00,\
00,01,00,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,\
00,00,00,00,05,20,00,00,00,20,02,00,00
"MachineAccessRestriction"=hex:01,00,04,80,44,00,00,00,54,00,00,00,00,00,00,00,\
14,00,00,00,02,00,30,00,02,00,00,00,00,00,14,00,03,00,00,00,01,01,00,00,00,\
00,00,05,07,00,00,00,00,00,14,00,07,00,00,00,01,01,00,00,00,00,00,01,00,00,\
00,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,00,\
05,20,00,00,00,20,02,00,00
"EnableDCOM"="Y"
[Ole\AppCompat]
[Ole\AppCompat\ActivationSecurityCheckExemptionList]
"{A50398B8-9075-4FBF-A7A1-456BF21937AD}"="1"
"{AD65A69D-3831-40D7-9629-9B0B50A93843}"="1"
"{0040D221-54A1-11D1-9DE0-006097042D69}"="1"
"{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3}"="1"
[Ole\NONREDIST]
"System.EnterpriseServices.Thunk.dll"=""
-----HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\AU\-----
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\-----
[Security Center]
"FirstRunDisabled"=dword:00000001
"AntiVirusDisableNotify"=dword:00000000
"FirewallDisableNotify"=dword:00000000
"UpdatesDisableNotify"=dword:00000000
"AntiVirusOverride"=dword:00000000
"FirewallOverride"=dword:00000000
[Security Center\Monitoring]
[Security Center\Monitoring\AhnlabAntiVirus]
[Security Center\Monitoring\ComputerAssociatesAntiVirus]
[Security Center\Monitoring\KasperskyAntiVirus]
[Security Center\Monitoring\McAfeeAntiVirus]
[Security Center\Monitoring\McAfeeFirewall]
[Security Center\Monitoring\PandaAntiVirus]
[Security Center\Monitoring\PandaFirewall]
[Security Center\Monitoring\SophosAntiVirus]
[Security Center\Monitoring\SymantecAntiVirus]
[Security Center\Monitoring\SymantecFirewall]
[Security Center\Monitoring\TinyFirewall]
[Security Center\Monitoring\TrendAntiVirus]
[Security Center\Monitoring\TrendFirewall]
[Security Center\Monitoring\ZoneLabsFirewall]
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\-----
[SystemRestore]
"DisableSR"=dword:00000001
"CreateFirstRunRp"=dword:00000001
"DSMin"=dword:000000c8
"DSMax"=dword:00000190
"RPSessionInterval"=dword:00000000
"RPGlobalInterval"=dword:00015180
"RPLifeInterval"=dword:0076a700
"CompressionBurst"=dword:0000003c
"TimerInterval"=dword:00000078
"DiskPercent"=dword:0000000c
"ThawInterval"=dword:00000384
"RestoreDiskSpaceError"=dword:00000000
"RestoreStatus"=dword:00000001
"RestoreSafeModeStatus"=dword:00000000
[SystemRestore\Cfg]
"DiskPercent"=dword:0000000c
"MachineGuid"="{87BF420B-1FC2-4A36-9E61-3F8AC3A7329F}"
[SystemRestore\SnapshotCallbacks]
@=""
-----HKEY_CURRENT_USER\Software\VB and VBA Program Settings-----
[VB and VBA Program Settings]
[VB and VBA Program Settings\CCleaner]
[VB and VBA Program Settings\CCleaner\Options]
[VB and VBA Program Settings\Euro Add-in]
[VB and VBA Program Settings\Euro Add-in\Wizard Options]
-----HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\-----
[MountPoints2]
[MountPoints2\A]
"BaseClass"="Drive"
[MountPoints2\C]
"BaseClass"="Drive"
[MountPoints2\D]
"BaseClass"="Drive"
[MountPoints2\E]
"BaseClass"="Drive"
[MountPoints2\F]
"BaseClass"="Drive"
[MountPoints2\G]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,01,00,01,01,ee,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,20,00,00,00,09,00,00,00
[MountPoints2\G\_Autorun]
[MountPoints2\G\_Autorun\DefaultIcon]
@="G:\LaunchU3.exe,0"
[MountPoints2\H]
"BaseClass"="Drive"
[MountPoints2\I]
"BaseClass"="Drive"
[MountPoints2\J]
"BaseClass"="Drive"
[MountPoints2\K]
"BaseClass"="Drive"
[MountPoints2\M]
"BaseClass"="Drive"
[MountPoints2\{01e75068-fd7a-11da-9f31-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,01,00,00,00,08,00,00,00
[MountPoints2\{01e75069-fd7a-11da-9f31-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,01,00,00,00,08,00,00,00
[MountPoints2\{0db3e424-d16e-11db-baf8-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,00,00,00
[MountPoints2\{1240b51c-eea1-11db-bb1c-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,00,00,00
[MountPoints2\{2d08fa3f-fd7b-11da-9f32-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,00,00,00
[MountPoints2\{3340c9d4-a72d-11db-babe-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,01,00,00,00,08,00,00,00
[MountPoints2\{3c598712-a6fc-11db-babd-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,00,00,00
[MountPoints2\{3de3b1a0-536b-11db-bc73-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,01,00,01,01,ee,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,20,00,00,00,09,00,00,00
[MountPoints2\{3de3b1a0-536b-11db-bc73-00112f96afe5}\_Autorun]
[MountPoints2\{3de3b1a0-536b-11db-bc73-00112f96afe5}\_Autorun\DefaultIcon]
@="M:\LaunchU3.exe,0"
[MountPoints2\{3de3b1a1-536b-11db-bc73-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,00,00,00
[MountPoints2\{44e7d23f-5554-11db-bbb2-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,cf,cf,5f,5f,\
5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,cf,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,df,\
df,5f,5f,5f,5f,cf,cf,cf,cf,cf,cf,cf,cf,5f,cf,cf,df,5f,5f,5f,5f,5f,5f,5f,5f,\
5f,5f,00,20,00,00,00,00,00,00,00
[MountPoints2\{689c9156-554a-11db-bbae-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,cf,cf,5f,5f,\
5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,cf,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,df,\
df,5f,5f,5f,5f,cf,cf,cf,cf,cf,cf,cf,cf,5f,cf,cf,df,5f,5f,5f,5f,5f,5f,5f,5f,\
5f,5f,00,60,00,00,00,00,00,00,00
[MountPoints2\{6c3f9a15-307a-11db-9fa4-00c049f362d3}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,01,00,00,00,08,00,00,00
[MountPoints2\{7679c314-47f5-11db-bc55-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,cf,cf,5f,5f,\
5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,cf,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,df,\
df,5f,5f,5f,5f,cf,cf,cf,cf,cf,cf,cf,cf,5f,cf,cf,df,5f,5f,5f,5f,5f,5f,5f,5f,\
5f,5f,00,60,00,00,00,00,00,00,00
[MountPoints2\{8dbc42c0-f990-11db-bb2e-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,00,00,00,00
[MountPoints2\{8dbc42c1-f990-11db-bb2e-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,00,00,00,00
[MountPoints2\{8dbc42c2-f990-11db-bb2e-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,00,00,00,00
[MountPoints2\{8dbc42c3-f990-11db-bb2e-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,00,00,00,00
[MountPoints2\{8dbc42cf-f990-11db-bb2e-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,00,00,00
[MountPoints2\{94c954be-5d1d-11db-ba38-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,cf,cf,5f,5f,\
5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,cf,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,df,\
df,5f,5f,5f,5f,cf,cf,cf,cf,cf,cf,cf,cf,5f,cf,cf,df,5f,5f,5f,5f,5f,5f,5f,5f,\
5f,5f,00,60,00,00,00,00,00,00,00
"_CommentFromDesktopINI"=""
[MountPoints2\{963bc3dd-77e2-11db-ba7e-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,00,00,00
[MountPoints2\{98eea835-fd78-11da-9f30-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,00,00,00,00
[MountPoints2\{9b3c5417-fe1c-11da-9f38-00c049f362d3}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,cf,cf,5f,5f,\
5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,cf,5f,5f,5f,5f,5f,cf,5f,5f,5f,5f,5f,df,\
df,5f,5f,5f,5f,cf,cf,cf,cf,cf,01,01,01,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,20,00,00,00,08,00,00,00
[MountPoints2\{9b3c5417-fe1c-11da-9f38-00c049f362d3}\_Autorun]
[MountPoints2\{9b3c5417-fe1c-11da-9f38-00c049f362d3}\_Autorun\DefaultIcon]
@="H:\Setup\Autorun.ico"
[MountPoints2\{ac26d344-d3c0-11db-bafc-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,00,00,00
[MountPoints2\{b05caac6-3939-11db-9fb4-00c049f362d3}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,01,00,00,00,08,00,00,00
"_LabelFromReg"="Disco esterno"
[MountPoints2\{bdc11676-41b2-11db-9fcf-00c049f362d3}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,00,00,00
[MountPoints2\{cc9758f6-fd7c-11da-b237-806d6172696f}]
"BaseClass"="Drive"
[MountPoints2\{cc9758f7-fd7c-11da-b237-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,01,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,20,00,00,00,09,00,00,00
"_CommentFromDesktopINI"=""
[MountPoints2\{cc9758f7-fd7c-11da-b237-806d6172696f}\cdname]
@="U.S.Robotics Installation CD"
[MountPoints2\{cc9758f7-fd7c-11da-b237-806d6172696f}\_Autorun]
[MountPoints2\{cc9758f7-fd7c-11da-b237-806d6172696f}\_Autorun\DefaultIcon]
@="D:\ctrun\ctrun.ico"
[MountPoints2\{cc9758f8-fd7c-11da-b237-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,cf,cf,5f,5f,\
5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,cf,5f,5f,5f,5f,5f,00,5f,5f,5f,5f,5f,df,\
df,5f,5f,5f,5f,01,01,00,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,60,00,00,00,08,04,00,00
[MountPoints2\{cc9758f9-fd7c-11da-b237-806d6172696f}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f,cf,5f,5f,5f,5f,01,01,00,5f,\
5f,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,60,00,00,00,0a,00,00,00
[MountPoints2\{cc9758fa-fd7c-11da-b237-806d6172696f}]
"BaseClass"="Drive"
[MountPoints2\{cf73ed62-5d23-11db-ba39-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,00,00,00,00
[MountPoints2\{cf73ed63-5d23-11db-ba39-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,00,00,00,00
[MountPoints2\{cf73ed64-5d23-11db-ba39-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,00,00,00,00
[MountPoints2\{cf73ed65-5d23-11db-ba39-00112f96afe5}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,00,00,00,00
[MountPoints2\{d5d9b26a-4192-11db-9fcc-00c049f362d3}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,00,00,00
[MountPoints2\{e8d0895e-3394-11db-9faa-00c049f362d3}]
"BaseClass"="Drive"
"_AutorunStatus"=hex:01,01,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
ff,ff,00,00,10,00,00,08,00,00,00
-----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions-----
[AdvancedOptions]
[AdvancedOptions\INTERNATIONAL]
"Text"="International*"
[AdvancedOptions\INTERNATIONAL\IDN]
"Text"="Send IDN server names"
[AdvancedOptions\INTERNATIONAL\IDN_INFOBAR]
"Text"="Show Information bar for encoded addresses"
[AdvancedOptions\INTERNATIONAL\IDN_INTRANET]
"Text"="Send IDN server names for Intranet addresses"
[AdvancedOptions\INTERNATIONAL\IDN_SHOWPUNY]
"Text"="Always show encoded addresses"
[AdvancedOptions\INTERNATIONAL\UTF8_MAILTO]
"Text"="Use UTF-8 for mailto links"
[AdvancedOptions\INTERNATIONAL\UTF8_URL]
"Text"="Send UTF-8 URLs"
-----HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions-----
-----HKLM\Software\Microsoft\Active Setup\Installed Components-----
[Installed Components]
[Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
"@="IE7 Uninstall Stub"
"ComponentID"="IEUDINIT"
"StubPath"="C:\WINDOWS\system32\ieudinit.exe"
[Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
#### HKCR\CLSID\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\InprocServer32 @