home *** CD-ROM | disk | FTP | other *** search
INI File | 2006-01-03 | 2.6 KB | 79 lines |
- [General]
- EngineType=1
-
- [Welchia]
- Reg1=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RPCPatch,"","",""
- Reg2=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RPCTFTPD,"","",""
- DeleteFile1=%winsysdir%\wins\svchost.exe
- DeleteFile2=%winsysdir%\wins\Dllhost.exe
-
- [LovGate]
- Reg1=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ll_reg,"","",""
- Reg2=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetMeeting\RemoteDesktop(RPC),"","",""
- Reg3=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Microsoft\NetWork File Wall Services,"","",""
- Reg4=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Windows\Management Instrumentation Driver Extension,"","",""
- DeleteFile1=%winsysdir%\NetServices.exe
- DeleteFile2=%winsysdir%\RAVMOND.EXE
- DeleteFile3=%winsysdir%\RAVMOND.EXE
- DeleteFile4=%winsysdir%\WinGate.exe
- DeleteFile5=%winsysdir%\WinDriver.exe
- DeleteFile6=%winsysdir%\WinHelp.exe
- DeleteFile7=%winsysdir%\winrpc.exe
- DeleteFile8=%winsysdir%\ily.dll
- DeleteFile9=%winsysdir%\task.dll
- DeleteFile10=%winsysdir%\reg.dll
- DeleteFile11=%winsysdir%\1.dll
- DeleteFile12=%winsysdir%\win32vxd.dll
- DeleteFile13=%winsysdir%\kernel66.dll
- DeleteFile14=%winsysdir%\kernel66.dll
- DeleteFile15=%winsysdir%\iky668.dll
- DeleteFile16=%winsysdir%\reg678.dll
- DeleteFile17=%winsysdir%\task688.dll
- DeleteFile18=%winsysdir%\111.dll
-
- [CodeRed]
- DeleteFile1=%inetpub%\scripts\root.exe
- DeleteFile2=%PF%\common~1\system\MSADC\root.exe
- ;DeleteFile3=%SYSTEMDIR%explorer.exe
- ;DeleteFile3 commented because in XP (64-bit OS), explorer.exe is kept in system32 folder!!!
- Reg1=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\Virtual Roots\C
- Reg2=HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\Virtual Roots\D
-
- [OpaServ]
- DeleteFile1=%SYSTEMDIR%\Tmp.ini
- ; this is Opaserv.M
- DeleteFile2=%SYSTEMDIR%\MSLICENF.COM
- DeleteFile3=%SYSTEMDIR%\BOOT.EXE
- BAT1=Autoexec.bat,MSLICENF
- BAT2=Autoexec.bat,BOOT.EXE
-
- [Sobig.e]
- DeleteFile1=%winsysdir%\cgtask.exe
- DeleteFile2=%winsysdir%\mmtask.exe
-
- [Winupie]
- DeleteFile1=%winsysdir%\AxConfig.dll,regsvr32 /s /u AxConfig.dll
-
- [Swen]
- DeleteFile1=%winsysdir%\SWEN*.DAT
-
- [JS.Fortnight]
- DeleteFile1=%PF%\sign.htm
- DeleteFile2=%PF%\sign.html
-
- [Novarg]
- DeleteFile1=%winsysdir%\shimgapi.dll
-
- [Pagabot]
- Reg1=HKEY_LOCAL_MACHINE\Software\Microsoft\windows\currentversion\run,Cryptographic Service,"",""
-
- [Parite.b]
- Reg1=HKEY_CURRENT_USER\Software\Microsoft\windows\currentversion\explorer,PINF,"",""
-
- [Parite.a]
- Reg1=HKEY_CURRENT_USER\Software\Microsoft\windows\currentversion\explorer,ZANF,"",""
-
- [Adware.SeekSeek]
- Reg1=HKEY_CURRENT_USER\Console,UUID,"",""
- Reg2=HKEY_CURRENT_USER\Console,lp,"",""
-