[Version]
Signature="$Windows NT$"
[DefaultInstall]
AddReg=AddReg_
DelReg=DelReg_
; DelFiles=DelFiles_
[AddReg_]
HKLM, "SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce"
HKCR, "exefile\shell\open\command",,0,"""%1"" %*"
HKCR, "comfile\shell\open\command",,0,"""%1"" %*"
HKCR, "cmdfile\shell\open\command",,0,"""%1"" %*"
HKCR, "batfile\shell\open\command",,0,"""%1"" %*"
HKCR, ".cfexe",,0,"exefile"
HKCU, "Software\Microsoft\Windows\CurrentVersion\Policies\System", DisableRegistryTools, 0x00010001, 0x00000000
HKCU, "Software\Policies\Microsoft\Windows\System", DisableCMD, 0x00010001, 0x00000000
HKCU, "Console", QuickEdit, 0x00010001, 0x00000000
HKCU, "Console", InsertMode, 0x00010001, 0x00000000
[DelReg_]
HKCU, %Processor%
HKLM, %Processor%
HKLM, %IFEO%\cmd.exe
HKLM, %IFEO%\cmd.execf
HKLM, %IFEO%\attrib.exe
HKLM, %IFEO%\chcp.com
HKLM, %IFEO%\cscript.exe
HKLM, %IFEO%\catchme.cfexe
HKLM, %IFEO%\erdnt.exe
HKLM, %IFEO%\erunt.cfexe
HKLM, %IFEO%\expand.exe
HKLM, %IFEO%\find.exe
HKLM, %IFEO%\Findstr.exe
HKLM, %IFEO%\sed.cfexe
HKLM, %IFEO%\grep.cfexe
HKLM, %IFEO%\psexec.cfexe
HKLM, %IFEO%\Nircmd.exe
HKLM, %IFEO%\Nircmd.com
HKLM, %IFEO%\Nircmd.cfexe
HKLM, %IFEO%\ComboFix.exe
HKLM, %IFEO%\Combo-Fix.exe
HKLM, %IFEO%\reg.exe
HKLM, %IFEO%\regedit.exe
HKLM, %IFEO%\regt.cfexe
HKLM, %IFEO%\rstrui.exe
HKLM, %IFEO%\rundll32.exe
HKLM, %IFEO%\taskmgr.exe
HKLM, %IFEO%\wscript.exe
HKLM, %IFEO%\xcopy.exe
HKLM, %IFEO%\dumphive.cfexe
HKLM, %IFEO%\extract.exe
HKLM, %IFEO%\fdsv.cfexe
HKLM, %IFEO%\handle.cfexe
HKLM, %IFEO%\listdlls.cfexe
HKLM, %IFEO%\moveex.cfexe
HKLM, %IFEO%\gsar.cfexe
HKLM, %IFEO%\mtee.cfexe
HKLM, %IFEO%\restartit.cfexe
HKLM, %IFEO%\setpath.cfexe
HKLM, %IFEO%\sf.cfexe
HKLM, %IFEO%\swreg.cfexe
HKLM, %IFEO%\swsc.exe
HKLM, %IFEO%\swsc.cfexe
HKLM, %IFEO%\swxcacls.cfexe
HKLM, %IFEO%\vfind.cfexe
HKLM, %IFEO%\zip.cfexe
HKLM, %IFEO%\swreg.exe
HKLM, %IFEO%\ctfmon.exe
[Strings]
IFEO = "Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options"
Processor = "Software\Microsoft\Command Processor"
[DelFiles_]
Nircmd.scr
[DestinationDirs]
DelFiles_=01