files missing

  1. #1
    ThuG_PoeT is offline Elite Member

    files missing

    virus striked at my pc and cleaned it up with sysclean but then i can't login to some of my files nor to my hard disk even to some of the software

    when i tried to login to my hard disk it's give's me this msg

    can not find script file C:\autorun.vbs



    Logfile of HijackThis v1.99.1
    Scan saved at 4:16:13 AM, on 4/9/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\IBM\SQLLIB\BIN\db2mgmtsvc.exe
    C:\Program Files\IBM\SQLLIB\BIN\db2sec.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5 a.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\HijackThis\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    F2 - REG:system.ini: UserInit=userinit.exe,autorun.bat
    O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: CDLPObj Object - {BE2ED590-CA49-46B5-8CCE-244FB2E0D1AA} - C:\WINDOWS\DLP.dll (file missing)
    O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp 5a.exe" /source=HKLM
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Runonce] C:\WINDOWS\system32\runouce.exe
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: Metacafe.lnk = D:\Metacafe\MetacafeAgent.exe
    O4 - Startup: Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe
    O4 - Startup: WordWeb.lnk = D:\Word\WordWeb\wweb32.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Metacafe.lnk = D:\Metacafe\MetacafeAgent.exe
    O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (file missing)
    O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe (file missing)
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O17 - HKLM\System\CCS\Services\Tcpip\..\{48F9A5B4-3CAE-4034-826A-69BD80A6767A}: NameServer = 202.188.0.147,202.188.1.25
    O17 - HKLM\System\CS1\Services\Tcpip\..\{48F9A5B4-3CAE-4034-826A-69BD80A6767A}: NameServer = 202.188.0.147,202.188.1.25
    O17 - HKLM\System\CS2\Services\Tcpip\..\{48F9A5B4-3CAE-4034-826A-69BD80A6767A}: NameServer = 202.188.0.147,202.188.1.25
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: DB2 Management Service (DB2COPY1) (DB2MGMTSVC_DB2COPY1) - International Business Machines Corporation - C:\Program Files\IBM\SQLLIB\BIN\db2mgmtsvc.exe
    O23 - Service: DB2 Security Server (DB2COPY1) (DB2NTSECSERVER_DB2COPY1) - International Business Machines Corporation - C:\Program Files\IBM\SQLLIB\BIN\db2sec.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: Office Source Engine (ose) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (file missing)
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: Messenger Sharing Folders USN Journal Reader service (usnjsvc) - Unknown owner - C:\Program Files\MSN Messenger\usnsvc.exe (file missing)


  2. #2
    VopThis is offline Senior Member (Canada)
    can not find script file C:\autorun.vbs
    THe missing script file is likely being call from the F2 line below (autorun.bat). Script files are notorious security risks.



    SELECT HijackThis FIX ITEMS: Scan with HijackThis and place a check next to these items:

    F2 - REG:system.ini: UserInit=userinit.exe,autorun.bat

    O2 - BHO: CDLPObj Object - {BE2ED590-CA49-46B5-8CCE-244FB2E0D1AA} - C:\WINDOWS\DLP.dll (file missing)

    Make sure that all browser windows and internet links are closed, even this one!
    CLICK ’FIX CHECKED’ with HijackThis.



    Let us know if the above fixes help improve matters.

  3. #3
    ThuG_PoeT is offline Elite Member
    ok i did the above but the problem is still there

  4. #4
    VopThis is offline Senior Member (Canada)
    Follow the instructions in post #3 at this link:
    http://forums.techguy.org/security/5...torun-vbs.html

  5. #5
    ThuG_PoeT is offline Elite Member
    Save 20% on AVG Internet Security 2012 Suite!
    Part1.txt file:


    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\C]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\D]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\E]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\F]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\G]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{05e2b21d-8a00-11db-9f5b-806d6172696f}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,df,df,df,5f,df,df,01 ,01,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,01,00,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{05e2b21d-8a00-11db-9f5b-806d6172696f}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{05e2b21d-8a00-11db-9f5b-806d6172696f}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{05e2b21d-8a00-11db-9f5b-806d6172696f}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{05e2b21e-8a00-11db-9f5b-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,01,00,01,01,ee,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,20,00,00,00,09,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{17276e6a-0503-11db-8286-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,01,01,01,ee,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{17276e6a-0503-11db-8286-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{17276e6a-0503-11db-8286-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{17276e6a-0503-11db-8286-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{234ac142-9a6f-11da-81f8-806d6172696f}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,cf,5f,5f,5f,5f,cf,cf,5f,5f,\
    5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,cf,5f,5f,5f,5f ,5f,00,5f,5f,5f,5f,5f,df,\
    df,5f,5f,5f,5f,01,01,01,5f,ee,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,60,00,00,00,08,04,00,00
    "_CommentFromDesktopINI"="Welcome to Groove Agent 2"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{271107bc-10c3-11db-8294-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,01,00,00,00,08,07,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{271107bc-10c3-11db-8294-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{271107bc-10c3-11db-8294-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{271107bc-10c3-11db-8294-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,cf,5f,5f,5f,5f,5f,00,\
    01,00,01,01,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,09,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell]
    @="Autoplay"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\Autoplay\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\AutoRun]
    "Extended"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\AutoRun\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\Explore]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\Explore\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\OPEN]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\OPEN\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{35f9e63c-c23a-11da-8247-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,00,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{35f9e63c-c23a-11da-8247-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{35f9e63c-c23a-11da-8247-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{35f9e63c-c23a-11da-8247-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4c0cda39-d88d-11da-8257-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,03,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4c0cda39-d88d-11da-8257-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4c0cda39-d88d-11da-8257-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4c0cda39-d88d-11da-8257-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4c0cda3a-d88d-11da-8257-001320c90e91}]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544aa-b9cb-11da-8246-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,cf,cf,cf,5f,cf,cf,cf ,5f,5f,5f,5f,5f,5f,5f,5f,\
    5f,5f,00,00,10,00,00,00,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544aa-b9cb-11da-8246-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544aa-b9cb-11da-8246-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544aa-b9cb-11da-8246-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544b2-b9cb-11da-8246-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,06,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544b2-b9cb-11da-8246-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544b2-b9cb-11da-8246-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544b2-b9cb-11da-8246-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4fe3da16-97c2-11db-9f97-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,07,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4fe3da16-97c2-11db-9f97-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4fe3da16-97c2-11db-9f97-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4fe3da16-97c2-11db-9f97-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{53260bca-b6c6-11db-b857-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,01,00,01,01,ee,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,20,00,00,00,09,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{53260bca-b6c6-11db-b857-001320c90e91}\_Autorun]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{53260bca-b6c6-11db-b857-001320c90e91}\_Autorun\DefaultIcon]
    @="G:\\appicon.ico"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a5-9a6e-11da-ad12-806d6172696f}]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a5-9a6e-11da-ad12-806d6172696f}\Shell]
    @="Open"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a5-9a6e-11da-ad12-806d6172696f}\Shell\AutoRun]
    "Extended"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a5-9a6e-11da-ad12-806d6172696f}\Shell\AutoRun\command]
    @="C:\\"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a5-9a6e-11da-ad12-806d6172696f}\Shell\explore]
    @="×ÊÔ´¹ÜÀíÆ÷(&X)"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a5-9a6e-11da-ad12-806d6172696f}\Shell\explore\Command]
    @="WScript.exe .\\autorun.vbs"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a5-9a6e-11da-ad12-806d6172696f}\Shell\open]
    @="´ò¿ª(&O)"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a5-9a6e-11da-ad12-806d6172696f}\Shell\open\Command]
    @="WScript.exe .\\autorun.vbs"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a5-9a6e-11da-ad12-806d6172696f}\Shell\open\Default]
    @="1"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a6-9a6e-11da-ad12-806d6172696f}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,df,df,df,5f,df,df,00 ,5f,5f,5f,5f,5f,5f,5f,5f,\
    5f,5f,00,01,00,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a6-9a6e-11da-ad12-806d6172696f}\Shell]
    @="Open"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a6-9a6e-11da-ad12-806d6172696f}\Shell\AutoRun]
    "Extended"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a6-9a6e-11da-ad12-806d6172696f}\Shell\AutoRun\command]
    @="D:\\"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a6-9a6e-11da-ad12-806d6172696f}\Shell\explore]
    @="×ÊÔ´¹ÜÀíÆ÷(&X)"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a6-9a6e-11da-ad12-806d6172696f}\Shell\explore\Command]
    @="WScript.exe .\\autorun.vbs"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a6-9a6e-11da-ad12-806d6172696f}\Shell\open]
    @="´ò¿ª(&O)"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a6-9a6e-11da-ad12-806d6172696f}\Shell\open\Command]
    @="WScript.exe .\\autorun.vbs"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a6-9a6e-11da-ad12-806d6172696f}\Shell\open\Default]
    @="1"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{66886b22-0dad-11db-8291-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,06,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{66886b22-0dad-11db-8291-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{66886b22-0dad-11db-8291-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{66886b22-0dad-11db-8291-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,00,\
    01,00,01,01,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,09,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell]
    @="AutoRun"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell\Auto]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell\Auto\command]
    @="sxs.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell\AutoRun]
    "Extended"=""
    @="Auto&Play"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell\AutoRun\command]
    @="C:\\WINDOWS\\system32\\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{78202426-9645-11db-9f8e-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,01,01,01,ee,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{78202426-9645-11db-9f8e-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{78202426-9645-11db-9f8e-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{78202426-9645-11db-9f8e-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{80d6490c-abed-11db-9fc8-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,01,00,00,00,08,07,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{80d6490c-abed-11db-9fc8-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{80d6490c-abed-11db-9fc8-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{80d6490c-abed-11db-9fc8-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283aa-c108-11db-b879-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,ee,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,df,df,df,5f,df,df,00 ,5f,5f,5f,5f,5f,5f,5f,5f,\
    5f,5f,00,01,00,00,00,08,05,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283aa-c108-11db-b879-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283aa-c108-11db-b879-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283aa-c108-11db-b879-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283ab-c108-11db-b879-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,df,df,df,5f,df,df,00 ,5f,5f,5f,5f,5f,5f,5f,5f,\
    5f,5f,00,01,00,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283ab-c108-11db-b879-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283ab-c108-11db-b879-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283ab-c108-11db-b879-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,00,\
    01,00,01,01,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,09,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell]
    @="Autoplay"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\Autoplay\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\AutoRun]
    "Extended"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\AutoRun\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\Explore]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\Explore\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\OPEN]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\OPEN\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{ad26393a-a306-11db-9fb7-001320c90e91}]
    "BaseClass"="Drive"
    "_CommentFromDesktopINI"=""
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,01,01,01,ee,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{ad26393a-a306-11db-9fb7-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{ad26393a-a306-11db-9fb7-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{ad26393a-a306-11db-9fb7-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670cd-ade1-11da-8244-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,01,01,01,ee,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670cd-ade1-11da-8244-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670cd-ade1-11da-8244-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670cd-ade1-11da-8244-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670f3-ade1-11da-8244-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,06,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670f3-ade1-11da-8244-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670f3-ade1-11da-8244-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670f3-ade1-11da-8244-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{c38b6924-a79c-11da-8239-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,00,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{c38b6924-a79c-11da-8239-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{c38b6924-a79c-11da-8239-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{c38b6924-a79c-11da-8239-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{c38b6925-a79c-11da-8239-001320c90e91}]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{cb444644-a05f-11da-8218-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,00,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{cb444644-a05f-11da-8218-001320c90e91}\Shell]
    @="AutoRun"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{cb444644-a05f-11da-8218-001320c90e91}\Shell\Auto]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{cb444644-a05f-11da-8218-001320c90e91}\Shell\Auto\command]
    @="sxs.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{cb444644-a05f-11da-8218-001320c90e91}\Shell\AutoRun]
    "Extended"=""
    @="Auto&Play"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{cb444644-a05f-11da-8218-001320c90e91}\Shell\AutoRun\command]
    @="C:\\WINDOWS\\system32\\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4daf-cecf-11da-8253-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,00,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,00,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4daf-cecf-11da-8253-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4daf-cecf-11da-8253-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4daf-cecf-11da-8253-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dbf-cecf-11da-8253-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,00,5f,5f,5f,ee,5f,cf,\
    cf,5f,5f,5f,5f,01,01,00,ee,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,01,00,00,00,08,07,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dbf-cecf-11da-8253-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dbf-cecf-11da-8253-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dbf-cecf-11da-8253-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dc0-cecf-11da-8253-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,00,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,01,01,00,ee,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,01,00,00,00,08,04,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dc0-cecf-11da-8253-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dc0-cecf-11da-8253-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dc0-cecf-11da-8253-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,03,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell]
    @="Open"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\AutoRun]
    "Extended"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\AutoRun\command]
    @="F:\\"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\explore]
    @="×ÊÔ´¹ÜÀíÆ÷(&X)"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\explore\Command]
    @="WScript.exe .\\autorun.vbs"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\open]
    @="´ò¿ª(&O)"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\open\Command]
    @="WScript.exe .\\autorun.vbs"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\open\Default]
    @="1"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{df27d72d-9fc4-11da-8217-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,03,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{df27d72d-9fc4-11da-8217-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{df27d72d-9fc4-11da-8217-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{df27d72d-9fc4-11da-8217-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{f0416dc8-a07a-11da-8219-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,00,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,01,01,00,ee,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,02,00,00
    "_CommentFromDesktopINI"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\CPC]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\CPC\Volume]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\CPC\Volume\{234ac1 42-9a6f-11da-81f8-806d6172696f}]
    "Data"=hex:00,00,00,00,5c,00,5c,00,3f,00,5c,00,49, 00,44,00,45,00,23,00,43,00,\
    64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,44,00,54 ,00,2d,00,53,00,54,00,5f,\
    00,52,00,57,00,23,00,44,00,56,00,44,00,5f,00,47,00 ,43,00,43,00,2d,00,34,00,\
    35,00,32,00,32,00,42,00,5f,00,5f,00,5f,00,5f,00,5f ,00,5f,00,5f,00,5f,00,5f,\
    00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,31,00,2e,00 ,30,00,36,00,5f,00,5f,00,\
    5f,00,5f,00,23,00,35,00,26,00,31,00,38,00,65,00,32 ,00,62,00,37,00,36,00,39,\
    00,26,00,30,00,26,00,30,00,2e,00,30,00,2e,00,30,00 ,23,00,7b,00,35,00,33,00,\
    66,00,35,00,36,00,33,00,30,00,64,00,2d,00,62,00,36 ,00,62,00,66,00,2d,00,31,\
    00,31,00,64,00,30,00,2d,00,39,00,34,00,66,00,32,00 ,2d,00,30,00,30,00,61,00,\
    30,00,63,00,39,00,31,00,65,00,66,00,62,00,38,00,62 ,00,7d,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,5c,00,5c,00,3f,00,5c,00,56,00 ,6f,00,6c,00,75,00,6d,00,\
    65,00,7b,00,32,00,33,00,34,00,61,00,63,00,31,00,34 ,00,32,00,2d,00,39,00,61,\
    00,36,00,66,00,2d,00,31,00,31,00,64,00,61,00,2d,00 ,38,00,31,00,66,00,38,00,\
    2d,00,38,00,30,00,36,00,64,00,36,00,31,00,37,00,32 ,00,36,00,39,00,36,00,66,\
    00,7d,00,5c,00,00,00,49,00,6e,00,76,00,61,00,6c,00 ,69,00,64,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,49,00,\
    6e,00,76,00,61,00,6c,00,69,00,64,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,01,00,00 ,00,10,00,00,00,1f,01,00,\
    00,bd,ad,db,ba,bd,ad,db,ba,bd,ad,db,ba,bd,ad,db,ba ,bd,ad,db,ba,00,00,00,00,\
    00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,00,\
    00
    "Generation"=dword:00000001

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\CPC\Volume\{53260b ca-b6c6-11db-b857-001320c90e91}]
    "Data"=hex:00,00,00,00,5c,00,5c,00,3f,00,5c,00,53, 00,43,00,53,00,49,00,23,00,\
    43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e ,00,5f,00,47,00,56,00,34,\
    00,36,00,34,00,32,00,59,00,26,00,50,00,72,00,6f,00 ,64,00,5f,00,4c,00,48,00,\
    46,00,30,00,35,00,33,00,4a,00,26,00,52,00,65,00,76 ,00,5f,00,32,00,2e,00,30,\
    00,42,00,23,00,35,00,26,00,33,00,30,00,37,00,33,00 ,38,00,37,00,32,00,63,00,\
    26,00,30,00,26,00,30,00,30,00,30,00,23,00,7b,00,35 ,00,33,00,66,00,35,00,36,\
    00,33,00,30,00,64,00,2d,00,62,00,36,00,62,00,66,00 ,2d,00,31,00,31,00,64,00,\
    30,00,2d,00,39,00,34,00,66,00,32,00,2d,00,30,00,30 ,00,61,00,30,00,63,00,39,\
    00,31,00,65,00,66,00,62,00,38,00,62,00,7d,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,5c,00,5c,00,3f,00,5c,00,56,00 ,6f,00,6c,00,75,00,6d,00,\
    65,00,7b,00,35,00,33,00,32,00,36,00,30,00,62,00,63 ,00,61,00,2d,00,62,00,36,\
    00,63,00,36,00,2d,00,31,00,31,00,64,00,62,00,2d,00 ,62,00,38,00,35,00,37,00,\
    2d,00,30,00,30,00,31,00,33,00,32,00,30,00,63,00,39 ,00,30,00,65,00,39,00,31,\
    00,7d,00,5c,00,00,00,49,00,6e,00,76,00,61,00,6c,00 ,69,00,64,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,49,00,\
    6e,00,76,00,61,00,6c,00,69,00,64,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,01,00,00 ,00,10,00,00,00,13,81,00,\
    00,bd,ad,db,ba,bd,ad,db,ba,bd,ad,db,ba,bd,ad,db,ba ,bd,ad,db,ba,00,00,00,00,\
    00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,00,\
    00
    "Generation"=dword:00000001

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\CPC\Volume\{57a3c3 a5-9a6e-11da-ad12-806d6172696f}]
    "Data"=hex:00,00,00,00,5c,00,5c,00,3f,00,5c,00,53, 00,54,00,4f,00,52,00,41,00,\
    47,00,45,00,23,00,56,00,6f,00,6c,00,75,00,6d,00,65 ,00,23,00,31,00,26,00,33,\
    00,30,00,61,00,39,00,36,00,35,00,39,00,38,00,26,00 ,30,00,26,00,53,00,69,00,\
    67,00,6e,00,61,00,74,00,75,00,72,00,65,00,31,00,36 ,00,35,00,37,00,31,00,36,\
    00,35,00,36,00,4f,00,66,00,66,00,73,00,65,00,74,00 ,37,00,45,00,30,00,30,00,\
    4c,00,65,00,6e,00,67,00,74,00,68,00,31,00,33,00,30 ,00,43,00,32,00,43,00,33,\
    00,36,00,30,00,30,00,23,00,7b,00,35,00,33,00,66,00 ,35,00,36,00,33,00,30,00,\
    64,00,2d,00,62,00,36,00,62,00,66,00,2d,00,31,00,31 ,00,64,00,30,00,2d,00,39,\
    00,34,00,66,00,32,00,2d,00,30,00,30,00,61,00,30,00 ,63,00,39,00,31,00,65,00,\
    66,00,62,00,38,00,62,00,7d,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,5c,00,5c,00,3f,00,5c,00,56,00 ,6f,00,6c,00,75,00,6d,00,\
    65,00,7b,00,35,00,37,00,61,00,33,00,63,00,33,00,61 ,00,35,00,2d,00,39,00,61,\
    00,36,00,65,00,2d,00,31,00,31,00,64,00,61,00,2d,00 ,61,00,64,00,31,00,32,00,\
    2d,00,38,00,30,00,36,00,64,00,36,00,31,00,37,00,32 ,00,36,00,39,00,36,00,66,\
    00,7d,00,5c,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,4e,00,\
    54,00,46,00,53,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,01,00,00 ,00,08,00,00,00,01,10,00,\
    00,ff,00,07,00,ff,00,00,00,16,00,00,00,94,3f,3c,5c ,00,00,00,00,00,00,00,30,\
    00,20,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,00,\
    00
    "Generation"=dword:00000001

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\CPC\Volume\{57a3c3 a6-9a6e-11da-ad12-806d6172696f}]
    "Data"=hex:00,00,00,00,5c,00,5c,00,3f,00,5c,00,53, 00,54,00,4f,00,52,00,41,00,\
    47,00,45,00,23,00,56,00,6f,00,6c,00,75,00,6d,00,65 ,00,23,00,31,00,26,00,33,\
    00,30,00,61,00,39,00,36,00,35,00,39,00,38,00,26,00 ,30,00,26,00,53,00,69,00,\
    67,00,6e,00,61,00,74,00,75,00,72,00,65,00,31,00,36 ,00,35,00,37,00,31,00,36,\
    00,35,00,36,00,4f,00,66,00,66,00,73,00,65,00,74,00 ,31,00,33,00,30,00,43,00,\
    32,00,44,00,33,00,32,00,30,00,30,00,4c,00,65,00,6e ,00,67,00,74,00,68,00,31,\
    00,32,00,33,00,36,00,36,00,41,00,43,00,45,00,30,00 ,30,00,23,00,7b,00,35,00,\
    33,00,66,00,35,00,36,00,33,00,30,00,64,00,2d,00,62 ,00,36,00,62,00,66,00,2d,\
    00,31,00,31,00,64,00,30,00,2d,00,39,00,34,00,66,00 ,32,00,2d,00,30,00,30,00,\
    61,00,30,00,63,00,39,00,31,00,65,00,66,00,62,00,38 ,00,62,00,7d,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,5c,00,5c,00,3f,00,5c,00,56,00 ,6f,00,6c,00,75,00,6d,00,\
    65,00,7b,00,35,00,37,00,61,00,33,00,63,00,33,00,61 ,00,36,00,2d,00,39,00,61,\
    00,36,00,65,00,2d,00,31,00,31,00,64,00,61,00,2d,00 ,61,00,64,00,31,00,32,00,\
    2d,00,38,00,30,00,36,00,64,00,36,00,31,00,37,00,32 ,00,36,00,39,00,36,00,66,\
    00,7d,00,5c,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,4e,00,\
    54,00,46,00,53,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,01,00,00 ,00,08,00,00,00,01,10,00,\
    00,ff,00,07,00,ff,00,00,00,16,00,00,00,b4,b0,0f,50 ,00,00,00,00,00,00,00,30,\
    00,20,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,00,\
    00
    "Generation"=dword:00000001

    Part1 Report
    Mon 04/09/2007 22:22:16.89

    No Autorun files found in C:\WINDOWS

    autorun files found in C:\WINDOWS\system32
    autorun.bin
    autorun.exe
    autorun.inf
    autorun.reg
    autorun.txt
    autorun.VVVbat
    autorun.wsh


    Contents of autorun.inf found in C:\WINDOWS\system32
    autorun·ç±©
    [autorun]
    open=

    shell\open=´ò¿ª(&O)
    shell\open\Command=WScript.exe .\autorun.vbs
    shell\open\Default=1
    shell\explore=×ÊÔ´¹ÜÀíÆ÷(&X)
    shell\explore\Command=WScript.exe .\autorun.vbs



    Files found on C:
    autorun.bin
    autorun.inf
    autorun.reg
    autorun.txt
    autorun.VVVbat
    autorun.wsh


    Contents of autorun.inf on C:
    autorun·ç±©
    [autorun]
    open=

    shell\open=´ò¿ª(&O)
    shell\open\Command=WScript.exe .\autorun.vbs
    shell\open\Default=1
    shell\explore=×ÊÔ´¹ÜÀíÆ÷(&X)
    shell\explore\Command=WScript.exe .\autorun.vbs



    Files found on D:
    autorun.bin
    autorun.exe
    autorun.inf
    autorun.reg
    autorun.txt
    autorun.VVVbat
    autorun.wsh


    Contents of autorun.inf on D:
    autorun·ç±©
    [autorun]
    open=

    shell\open=´ò¿ª(&O)
    shell\open\Command=WScript.exe .\autorun.vbs
    shell\open\Default=1
    shell\explore=×ÊÔ´¹ÜÀíÆ÷(&X)
    shell\explore\Command=WScript.exe .\autorun.vbs


    Part2.txt file:

    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\C]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\D]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\E]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\F]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\G]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{05e2b21d-8a00-11db-9f5b-806d6172696f}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,df,df,df,5f,df,df,01 ,01,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,01,00,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{05e2b21d-8a00-11db-9f5b-806d6172696f}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{05e2b21d-8a00-11db-9f5b-806d6172696f}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{05e2b21d-8a00-11db-9f5b-806d6172696f}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{05e2b21e-8a00-11db-9f5b-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,01,00,01,01,ee,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,20,00,00,00,09,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{17276e6a-0503-11db-8286-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,01,01,01,ee,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{17276e6a-0503-11db-8286-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{17276e6a-0503-11db-8286-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{17276e6a-0503-11db-8286-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{234ac142-9a6f-11da-81f8-806d6172696f}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,cf,5f,5f,5f,5f,cf,cf,5f,5f,\
    5f,cf,cf,cf,5f,5f,5f,cf,cf,cf,5f,5f,cf,5f,5f,5f,5f ,5f,00,5f,5f,5f,5f,5f,df,\
    df,5f,5f,5f,5f,01,01,01,5f,ee,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,60,00,00,00,08,04,00,00
    "_CommentFromDesktopINI"="Welcome to Groove Agent 2"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{271107bc-10c3-11db-8294-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,01,00,00,00,08,07,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{271107bc-10c3-11db-8294-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{271107bc-10c3-11db-8294-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{271107bc-10c3-11db-8294-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,cf,5f,5f,5f,5f,5f,00,\
    01,00,01,01,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,09,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell]
    @="Autoplay"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\Autoplay\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\AutoRun]
    "Extended"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\AutoRun\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\Explore]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\Explore\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\OPEN]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{2e07e030-8e44-11db-9f68-001320c90e91}\Shell\OPEN\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{35f9e63c-c23a-11da-8247-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,00,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{35f9e63c-c23a-11da-8247-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{35f9e63c-c23a-11da-8247-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{35f9e63c-c23a-11da-8247-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4c0cda39-d88d-11da-8257-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,03,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4c0cda39-d88d-11da-8257-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4c0cda39-d88d-11da-8257-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4c0cda39-d88d-11da-8257-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4c0cda3a-d88d-11da-8257-001320c90e91}]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544aa-b9cb-11da-8246-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,cf,cf,cf,5f,cf,cf,cf ,5f,5f,5f,5f,5f,5f,5f,5f,\
    5f,5f,00,00,10,00,00,00,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544aa-b9cb-11da-8246-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544aa-b9cb-11da-8246-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544aa-b9cb-11da-8246-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544b2-b9cb-11da-8246-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,06,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544b2-b9cb-11da-8246-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544b2-b9cb-11da-8246-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4ca544b2-b9cb-11da-8246-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4fe3da16-97c2-11db-9f97-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,07,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4fe3da16-97c2-11db-9f97-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4fe3da16-97c2-11db-9f97-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{4fe3da16-97c2-11db-9f97-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{53260bca-b6c6-11db-b857-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,01,00,01,01,ee,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,20,00,00,00,09,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{53260bca-b6c6-11db-b857-001320c90e91}\_Autorun]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{53260bca-b6c6-11db-b857-001320c90e91}\_Autorun\DefaultIcon]
    @="G:\\appicon.ico"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a5-9a6e-11da-ad12-806d6172696f}]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{57a3c3a6-9a6e-11da-ad12-806d6172696f}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,df,df,df,5f,df,df,00 ,5f,5f,5f,5f,5f,5f,5f,5f,\
    5f,5f,00,01,00,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{66886b22-0dad-11db-8291-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,06,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{66886b22-0dad-11db-8291-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{66886b22-0dad-11db-8291-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{66886b22-0dad-11db-8291-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,00,\
    01,00,01,01,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,09,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell]
    @="AutoRun"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell\Auto]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell\Auto\command]
    @="sxs.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell\AutoRun]
    "Extended"=""
    @="Auto&Play"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{72dd28b8-a3f8-11db-9fbc-001320c90e91}\Shell\AutoRun\command]
    @="C:\\WINDOWS\\system32\\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{78202426-9645-11db-9f8e-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,01,01,01,ee,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{78202426-9645-11db-9f8e-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{78202426-9645-11db-9f8e-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{78202426-9645-11db-9f8e-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{80d6490c-abed-11db-9fc8-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,01,00,00,00,08,07,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{80d6490c-abed-11db-9fc8-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{80d6490c-abed-11db-9fc8-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{80d6490c-abed-11db-9fc8-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283aa-c108-11db-b879-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,ee,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,df,df,df,5f,df,df,00 ,5f,5f,5f,5f,5f,5f,5f,5f,\
    5f,5f,00,01,00,00,00,08,05,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283aa-c108-11db-b879-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283aa-c108-11db-b879-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283aa-c108-11db-b879-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283ab-c108-11db-b879-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,df,df,df,5f,df,df,00 ,5f,5f,5f,5f,5f,5f,5f,5f,\
    5f,5f,00,01,00,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283ab-c108-11db-b879-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283ab-c108-11db-b879-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{954283ab-c108-11db-b879-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,00,\
    01,00,01,01,ee,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,09,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell]
    @="Autoplay"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\Autoplay\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\AutoRun]
    "Extended"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\AutoRun\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\Explore]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\Explore\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\OPEN]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{9de0ea54-b4df-11db-b852-001320c90e91}\Shell\OPEN\command]
    @="F:\\MySexy.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{ad26393a-a306-11db-9fb7-001320c90e91}]
    "BaseClass"="Drive"
    "_CommentFromDesktopINI"=""
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,01,01,01,ee,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{ad26393a-a306-11db-9fb7-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{ad26393a-a306-11db-9fb7-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{ad26393a-a306-11db-9fb7-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670cd-ade1-11da-8244-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,cf,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,cf,cf,cf,cf,cf,01,01,01,ee,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670cd-ade1-11da-8244-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670cd-ade1-11da-8244-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670cd-ade1-11da-8244-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670f3-ade1-11da-8244-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,06,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670f3-ade1-11da-8244-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670f3-ade1-11da-8244-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{bde670f3-ade1-11da-8244-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{c38b6924-a79c-11da-8239-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,00,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{c38b6924-a79c-11da-8239-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{c38b6924-a79c-11da-8239-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{c38b6924-a79c-11da-8239-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{c38b6925-a79c-11da-8239-001320c90e91}]
    "BaseClass"="Drive"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{cb444644-a05f-11da-8218-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,00,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{cb444644-a05f-11da-8218-001320c90e91}\Shell]
    @="AutoRun"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{cb444644-a05f-11da-8218-001320c90e91}\Shell\Auto]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{cb444644-a05f-11da-8218-001320c90e91}\Shell\Auto\command]
    @="sxs.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{cb444644-a05f-11da-8218-001320c90e91}\Shell\AutoRun]
    "Extended"=""
    @="Auto&Play"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{cb444644-a05f-11da-8218-001320c90e91}\Shell\AutoRun\command]
    @="C:\\WINDOWS\\system32\\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4daf-cecf-11da-8253-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,00,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,00,00,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4daf-cecf-11da-8253-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4daf-cecf-11da-8253-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4daf-cecf-11da-8253-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dbf-cecf-11da-8253-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,00,5f,5f,5f,ee,5f,cf,\
    cf,5f,5f,5f,5f,01,01,00,ee,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,01,00,00,00,08,07,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dbf-cecf-11da-8253-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dbf-cecf-11da-8253-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dbf-cecf-11da-8253-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dc0-cecf-11da-8253-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,00,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,01,01,00,ee,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,01,00,00,00,08,04,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dc0-cecf-11da-8253-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dc0-cecf-11da-8253-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{d7ef4dc0-cecf-11da-8253-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,03,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell]
    @="Open"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\AutoRun]
    "Extended"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\AutoRun\command]
    @="F:\\"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\explore]
    @="×ÊÔ´¹ÜÀíÆ÷(&X)"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\explore\Command]
    @="WScript.exe .\\autorun.vbs"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\open]
    @="´ò¿ª(&O)"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\open\Command]
    @="WScript.exe .\\autorun.vbs"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{da6c0bad-e34d-11db-b8a2-001320c90e91}\Shell\open\Default]
    @="1"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{df27d72d-9fc4-11da-8217-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,01,00,01,01,ee,ff,ff,\
    ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,03,00,00

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{df27d72d-9fc4-11da-8217-001320c90e91}\shell]
    @="None"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{df27d72d-9fc4-11da-8217-001320c90e91}\shell\Autoplay]
    "MUIVerb"="@shell32.dll,-8504"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{df27d72d-9fc4-11da-8217-001320c90e91}\shell\Autoplay\DropTarget]
    "CLSID"="{f26a669a-bcbb-4e37-abf9-7325da15f931}"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{f0416dc8-a07a-11da-8219-001320c90e91}]
    "BaseClass"="Drive"
    "_AutorunStatus"=hex:01,00,01,00,00,01,00,df,df,5f ,df,5f,5f,5f,5f,df,df,5f,5f,\
    5f,df,df,df,5f,5f,5f,df,df,df,5f,5f,df,5f,5f,5f,5f ,5f,00,5f,5f,5f,5f,5f,cf,\
    cf,5f,5f,5f,5f,01,01,00,ee,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,ff,\
    ff,ff,00,00,10,00,00,08,02,00,00
    "_CommentFromDesktopINI"=""

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\CPC]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\CPC\Volume]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\CPC\Volume\{234ac1 42-9a6f-11da-81f8-806d6172696f}]
    "Data"=hex:00,00,00,00,5c,00,5c,00,3f,00,5c,00,49, 00,44,00,45,00,23,00,43,00,\
    64,00,52,00,6f,00,6d,00,48,00,4c,00,2d,00,44,00,54 ,00,2d,00,53,00,54,00,5f,\
    00,52,00,57,00,23,00,44,00,56,00,44,00,5f,00,47,00 ,43,00,43,00,2d,00,34,00,\
    35,00,32,00,32,00,42,00,5f,00,5f,00,5f,00,5f,00,5f ,00,5f,00,5f,00,5f,00,5f,\
    00,5f,00,5f,00,5f,00,5f,00,5f,00,5f,00,31,00,2e,00 ,30,00,36,00,5f,00,5f,00,\
    5f,00,5f,00,23,00,35,00,26,00,31,00,38,00,65,00,32 ,00,62,00,37,00,36,00,39,\
    00,26,00,30,00,26,00,30,00,2e,00,30,00,2e,00,30,00 ,23,00,7b,00,35,00,33,00,\
    66,00,35,00,36,00,33,00,30,00,64,00,2d,00,62,00,36 ,00,62,00,66,00,2d,00,31,\
    00,31,00,64,00,30,00,2d,00,39,00,34,00,66,00,32,00 ,2d,00,30,00,30,00,61,00,\
    30,00,63,00,39,00,31,00,65,00,66,00,62,00,38,00,62 ,00,7d,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,5c,00,5c,00,3f,00,5c,00,56,00 ,6f,00,6c,00,75,00,6d,00,\
    65,00,7b,00,32,00,33,00,34,00,61,00,63,00,31,00,34 ,00,32,00,2d,00,39,00,61,\
    00,36,00,66,00,2d,00,31,00,31,00,64,00,61,00,2d,00 ,38,00,31,00,66,00,38,00,\
    2d,00,38,00,30,00,36,00,64,00,36,00,31,00,37,00,32 ,00,36,00,39,00,36,00,66,\
    00,7d,00,5c,00,00,00,49,00,6e,00,76,00,61,00,6c,00 ,69,00,64,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,49,00,\
    6e,00,76,00,61,00,6c,00,69,00,64,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,01,00,00 ,00,10,00,00,00,1f,01,00,\
    00,bd,ad,db,ba,bd,ad,db,ba,bd,ad,db,ba,bd,ad,db,ba ,bd,ad,db,ba,00,00,00,00,\
    00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,00,\
    00
    "Generation"=dword:00000002

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\CPC\Volume\{53260b ca-b6c6-11db-b857-001320c90e91}]
    "Data"=hex:00,00,00,00,5c,00,5c,00,3f,00,5c,00,53, 00,43,00,53,00,49,00,23,00,\
    43,00,64,00,52,00,6f,00,6d,00,26,00,56,00,65,00,6e ,00,5f,00,47,00,56,00,34,\
    00,36,00,34,00,32,00,59,00,26,00,50,00,72,00,6f,00 ,64,00,5f,00,4c,00,48,00,\
    46,00,30,00,35,00,33,00,4a,00,26,00,52,00,65,00,76 ,00,5f,00,32,00,2e,00,30,\
    00,42,00,23,00,35,00,26,00,33,00,30,00,37,00,33,00 ,38,00,37,00,32,00,63,00,\
    26,00,30,00,26,00,30,00,30,00,30,00,23,00,7b,00,35 ,00,33,00,66,00,35,00,36,\
    00,33,00,30,00,64,00,2d,00,62,00,36,00,62,00,66,00 ,2d,00,31,00,31,00,64,00,\
    30,00,2d,00,39,00,34,00,66,00,32,00,2d,00,30,00,30 ,00,61,00,30,00,63,00,39,\
    00,31,00,65,00,66,00,62,00,38,00,62,00,7d,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,5c,00,5c,00,3f,00,5c,00,56,00 ,6f,00,6c,00,75,00,6d,00,\
    65,00,7b,00,35,00,33,00,32,00,36,00,30,00,62,00,63 ,00,61,00,2d,00,62,00,36,\
    00,63,00,36,00,2d,00,31,00,31,00,64,00,62,00,2d,00 ,62,00,38,00,35,00,37,00,\
    2d,00,30,00,30,00,31,00,33,00,32,00,30,00,63,00,39 ,00,30,00,65,00,39,00,31,\
    00,7d,00,5c,00,00,00,49,00,6e,00,76,00,61,00,6c,00 ,69,00,64,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,49,00,\
    6e,00,76,00,61,00,6c,00,69,00,64,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,01,00,00 ,00,10,00,00,00,13,81,00,\
    00,bd,ad,db,ba,bd,ad,db,ba,bd,ad,db,ba,bd,ad,db,ba ,bd,ad,db,ba,00,00,00,00,\
    00,00,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,00,\
    00
    "Generation"=dword:00000002

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\CPC\Volume\{57a3c3 a5-9a6e-11da-ad12-806d6172696f}]
    "Data"=hex:00,00,00,00,5c,00,5c,00,3f,00,5c,00,53, 00,54,00,4f,00,52,00,41,00,\
    47,00,45,00,23,00,56,00,6f,00,6c,00,75,00,6d,00,65 ,00,23,00,31,00,26,00,33,\
    00,30,00,61,00,39,00,36,00,35,00,39,00,38,00,26,00 ,30,00,26,00,53,00,69,00,\
    67,00,6e,00,61,00,74,00,75,00,72,00,65,00,31,00,36 ,00,35,00,37,00,31,00,36,\
    00,35,00,36,00,4f,00,66,00,66,00,73,00,65,00,74,00 ,37,00,45,00,30,00,30,00,\
    4c,00,65,00,6e,00,67,00,74,00,68,00,31,00,33,00,30 ,00,43,00,32,00,43,00,33,\
    00,36,00,30,00,30,00,23,00,7b,00,35,00,33,00,66,00 ,35,00,36,00,33,00,30,00,\
    64,00,2d,00,62,00,36,00,62,00,66,00,2d,00,31,00,31 ,00,64,00,30,00,2d,00,39,\
    00,34,00,66,00,32,00,2d,00,30,00,30,00,61,00,30,00 ,63,00,39,00,31,00,65,00,\
    66,00,62,00,38,00,62,00,7d,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,5c,00,5c,00,3f,00,5c,00,56,00 ,6f,00,6c,00,75,00,6d,00,\
    65,00,7b,00,35,00,37,00,61,00,33,00,63,00,33,00,61 ,00,35,00,2d,00,39,00,61,\
    00,36,00,65,00,2d,00,31,00,31,00,64,00,61,00,2d,00 ,61,00,64,00,31,00,32,00,\
    2d,00,38,00,30,00,36,00,64,00,36,00,31,00,37,00,32 ,00,36,00,39,00,36,00,66,\
    00,7d,00,5c,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,4e,00,\
    54,00,46,00,53,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,01,00,00 ,00,08,00,00,00,01,10,00,\
    00,ff,00,07,00,ff,00,00,00,16,00,00,00,94,3f,3c,5c ,00,00,00,00,00,00,00,30,\
    00,20,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,00,\
    00
    "Generation"=dword:00000002

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\CPC\Volume\{57a3c3 a6-9a6e-11da-ad12-806d6172696f}]
    "Data"=hex:00,00,00,00,5c,00,5c,00,3f,00,5c,00,53, 00,54,00,4f,00,52,00,41,00,\
    47,00,45,00,23,00,56,00,6f,00,6c,00,75,00,6d,00,65 ,00,23,00,31,00,26,00,33,\
    00,30,00,61,00,39,00,36,00,35,00,39,00,38,00,26,00 ,30,00,26,00,53,00,69,00,\
    67,00,6e,00,61,00,74,00,75,00,72,00,65,00,31,00,36 ,00,35,00,37,00,31,00,36,\
    00,35,00,36,00,4f,00,66,00,66,00,73,00,65,00,74,00 ,31,00,33,00,30,00,43,00,\
    32,00,44,00,33,00,32,00,30,00,30,00,4c,00,65,00,6e ,00,67,00,74,00,68,00,31,\
    00,32,00,33,00,36,00,36,00,41,00,43,00,45,00,30,00 ,30,00,23,00,7b,00,35,00,\
    33,00,66,00,35,00,36,00,33,00,30,00,64,00,2d,00,62 ,00,36,00,62,00,66,00,2d,\
    00,31,00,31,00,64,00,30,00,2d,00,39,00,34,00,66,00 ,32,00,2d,00,30,00,30,00,\
    61,00,30,00,63,00,39,00,31,00,65,00,66,00,62,00,38 ,00,62,00,7d,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,5c,00,5c,00,3f,00,5c,00,56,00 ,6f,00,6c,00,75,00,6d,00,\
    65,00,7b,00,35,00,37,00,61,00,33,00,63,00,33,00,61 ,00,36,00,2d,00,39,00,61,\
    00,36,00,65,00,2d,00,31,00,31,00,64,00,61,00,2d,00 ,61,00,64,00,31,00,32,00,\
    2d,00,38,00,30,00,36,00,64,00,36,00,31,00,37,00,32 ,00,36,00,39,00,36,00,66,\
    00,7d,00,5c,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,4e,00,\
    54,00,46,00,53,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00 ,00,00,00,00,00,00,00,00,\
    00,00,00,00,00,00,00,00,00,00,00,00,00,00,01,00,00 ,00,08,00,00,00,01,10,00,\
    00,ff,00,07,00,ff,00,00,00,16,00,00,00,b4,b0,0f,50 ,00,00,00,00,00,00,00,30,\
    00,20,00,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff ,ff,ff,ff,ff,ff,ff,ff,00,\
    00
    "Generation"=dword:00000002

    Part2 Report
    Mon 04/09/2007 22:24:13.14

    No Autorun files found in C:\WINDOWS

    No Autorun files found in C:\WINDOWS\system32

    No Autorun files found in root of C:


    No Autorun files found in root of D:




    Hijackthis log:

    Logfile of HijackThis v1.99.1
    Scan saved at 10:24:51 PM, on 4/9/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\IBM\SQLLIB\BIN\db2mgmtsvc.exe
    C:\Program Files\IBM\SQLLIB\BIN\db2sec.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    D:\Word\WordWeb\wweb32.exe
    C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\HijackThis\hijackthis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 www.alcohol-soft.com
    O1 - Hosts: 127.255.255.255 images.alcohol-soft.com
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp 5a.exe" /source=HKLM
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\RunOnce: [TSC - PE_Chir.B] command /c md C:\WINDOWS\system32\runouce.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: Metacafe.lnk = D:\Metacafe\MetacafeAgent.exe
    O4 - Startup: Registration Heroes of Might & Magic 5.LNK = C:\Program Files\Ubisoft\Heroes of Might and Magic V\registration\RegistrationReminder.exe
    O4 - Startup: WordWeb.lnk = D:\Word\WordWeb\wweb32.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Metacafe.lnk = D:\Metacafe\MetacafeAgent.exe
    O8 - Extra context menu item: &WordWeb... - res://C:\WINDOWS\wweb32.dll/lookup.html
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
    O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\flashget.exe
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O17 - HKLM\System\CCS\Services\Tcpip\..\{48F9A5B4-3CAE-4034-826A-69BD80A6767A}: NameServer = 202.188.0.147,202.188.1.25
    O17 - HKLM\System\CS1\Services\Tcpip\..\{48F9A5B4-3CAE-4034-826A-69BD80A6767A}: NameServer = 202.188.0.147,202.188.1.25
    O17 - HKLM\System\CS2\Services\Tcpip\..\{48F9A5B4-3CAE-4034-826A-69BD80A6767A}: NameServer = 202.188.0.147,202.188.1.25
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: DB2 Management Service (DB2COPY1) (DB2MGMTSVC_DB2COPY1) - International Business Machines Corporation - C:\Program Files\IBM\SQLLIB\BIN\db2mgmtsvc.exe
    O23 - Service: DB2 Security Server (DB2COPY1) (DB2NTSECSERVER_DB2COPY1) - International Business Machines Corporation - C:\Program Files\IBM\SQLLIB\BIN\db2sec.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

+ Reply to Thread