Dear Everyone!
Trying to help a family member with a "crashed disk" thought UBCD could be very useful, however after downloading (the Mirror from ZD Net, download on October 19th), when I tried to "install" I got a warning regarding the file:
plugin\AntiSpyware\XBlock\xclean_micro.exe, 09B550B74C729232F2C88A9B98AE4F0C
(My Norton also blocked the Hash sum test, but avter Trojan warning I was a bit worried anyway )
And My Norton Antivirus package informs me that there is a Trojan called: Trojan.Zlob.N that gets installed (thus this file gets removed by Norton)
I paste in some "Message winwos below", sorry for the Norwegian language.
Thanks beforehand for any suggestions - hints
kind regards
ATO/Arnfinn (from Norway)
***********
Trojan Detected in UBCD4WIN olugi is-09ETL.tmp
Trojan.Zlob.N
plugin\AntiSpyware\XBlock\xclean_micro.exe, 09B550B74C729232F2C88A9B98AE4F0C has been removed.
The listing on that particular Troja is as follows:
**********
Discovered: May 8, 2007
Updated: May 8, 2007 4:56:19 PM
Type: Trojan
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
When the Trojan is executed, it installs the following toolbar in Internet Explorer:
Protection Bar
The Trojan then creates the following files:
* %CurrentFolder%\smmain.exe
* %CurrentFolder%\smmon.exe
* %CurrentFolder%\splug.dll
* %CurrentFolder%\spunst.exe
* %CurrentFolder%\smunst.exe
* %CurrentFolder%\spunst.exe
It may also drop the following file:
%ProgramFiles%\Video ActiveX Access\iesmin.exe
Next, the Trojan creates the following registry entry so that it executes whenever Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\"rare" = "%CurrentFolder%\smmain.exe"
It also creates the following registry entry:
HKEY_CURRENT_USER\Software\Protection Tools\"65005" = "1"
The Trojan also creates the following registry subkeys:
HKEY_CLASSES_ROOT\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{F0993251-2512-4710-AF6E-0A13EA199D02}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0993251-2512-4710-AF6E-0A13EA199D02}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{F0993251-2512-4710-AF6E-0A13EA199D02}
Page 1 of 1
Got Trojan Warning from Norton Anitvirus during install Got Trojan Warning from Norton Anitvirus during install
#2
Posted 20 October 2007 - 12:32 PM
Please read the FAQ's see http://www.ubcd4win.com/faq.htm#false
As proof... see Softpedia's info here http://www.softpedia...lean-76994.html
Please report the false positive to Norton... if they won't correct the issue... consider using a product that the company will respond to their users complaints
As proof... see Softpedia's info here http://www.softpedia...lean-76994.html
Please report the false positive to Norton... if they won't correct the issue... consider using a product that the company will respond to their users complaints
Plan A is always more effective when the device you are working on understands that Plan B involves either a large hammer or screwdriver....
#3
Posted 20 October 2007 - 02:46 PM
Here's the results from running the suspect file through SysAnalyzer
And the API's...
I see nothing malicious...
CODE
File: xclean_micro.exe
Size: 750616 Bytes
MD5: 09B550B74C729232F2C88A9B98AE4F0C
Packer: File not found C:\iDEFENSE\SysAnalyzer\peid.exe
File Properties: CompanyName XBlock.com
FileDescription X-Cleaner
FileVersion 1.1.1.11
InternalName InternalName
LegalCopyright (C) 2003 by X-Block.com
OriginalFilename OriginalFileName
ProductName ProductName
ProductVersion
Exploit Signatures:
---------------------------------------------------------------------------
Scanning for 19 signatures
Scan Complete: 1896Kb in 0.094 seconds
Urls
--------------------------------------------------
IEZON|http://*.systemdoctor.com
IEZON| http://www.winantivirus.com
IEZON| http://www.winantiviruspro.com
Please use the update feature or visit http://www.xblock.com/ to receive the needed updates.(This program will stop functioning soon!
RegKeys
--------------------------------------------------
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , *.system-processes
REGKE|HKEY_CURRENT_USER\Software\Maxthon\Plugin\toolbar\{44BE0690-5429-47f0-85BB-3FFD8020233E}
REGKE|HKEY_CURRENT_USER\Software\VoiceIP
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\webHancer Agent
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WUSE.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WUSN.1
NEWPR|2337|WhistleSoftware
DIREC|%ProgramFiles%\WhistleSoftware\
RKSOF|WhistleSoftware
UINST|Whistle Software
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WinA
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\pup
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\woualo
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Yazzle Snowball Wars
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yazzle Snowball Wars
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Yazzle Sudoku
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\YazzleSudokuGame
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , dns-look-up.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , netbios-wait.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , netsearchsoft.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.dns-look-up.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.netbios-wait.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.netsearchsoft.com
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ccaccess.dll
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Emitt
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform , ADVPLUGIN|K115|165|S-866237264|dialno
REGKE|HKEY_CURRENT_USER\Software\SiteIcons\Dialers
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pmxy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-pmxy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/comload.dll
REGKE|HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/unidist.ocx
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\PMT
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Ebates.
REGKE|HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\alertSpy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\alertSpy.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiVerminser.exe\
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusProtection.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Telecom Advance\Antivirus Protection
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusSolution.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\Ad-Protect.Addin.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ad-protect.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ContraVirus.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\ExpertAntivirus.Addin.1
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\AdLoader
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Trace7
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\1das\AdLoader
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\dnl7\tracer
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ExpertAntivirus.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\myCleanerPC
REGKE|HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\Pestbot
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Pestbot.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FindExtensions\Static\RegFreeze
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\Spy-Shield.Addin.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Spy-Shield.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\SpyAxe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\SpyAxe.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\spyaxe.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyDawn.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyFalcon.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHazard.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHeal.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Spyware Cleaner
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareQuake.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler , {E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Spyware-Secure
AUTST|Software Soft Stop
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareLocked 3.5.exe
REGKE|HKEY_CURRENT_USER\Software\VB and VBA Program Settings\VBouncer
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\virus-bursters.exe\
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\VirusProtectPro 3.4.exe 3.4
DIREC|%ProgramFiles%\Common Files\WinSoftware\
RKSOF|WinSoftware\WinAntiSpyware 2005\
DIREC|%allusersprofile%\Application Data\WinSoftware\WinAntiVirus 2005\
DIREC|%userprofile%\Application Data\WinSoftware\WinAntiVirus 2005\
RKSOF|winsoftware\winantivirus 2005
RKSOF|winsoftware\winantivirus 2005 trial
DIREC|%commonprogramfiles%\winsoftware\
RKSOF|WinSoftware
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\WinHound spyware remover
Scanning for %s ...cIt is recommended that you reboot your PC after the removal of software.
ExeRefs
--------------------------------------------------
FILEN|surfairys.exe
AUTST|cashplusmedia.exe
FILEN|ssk.exe
FILEN|ssk3repairinstall.exe
FILEN|ssk3_b5 seedcorn 4.exe
FILEN|surfsidekick.exe
FILEN|syncroad.exe
FILEN|tagasaurus.exe
FILEN|tagasuarus97.exe
FILEN|133_funtarget_4_0_4_0.exe
FILEN|tsinstall_4_0_3_8_b17.exe
FILEN|tsinstall_4_0_4_0_b4.exe
FILEN|%systemroot%syssfitb.exe
FILEN|tgdc.exe
FILEN|ucmoreiex.exe
RKSOF|Microsoft\Windows\CurrentVersion\App Paths\TinkoPal.exe
RKSOF|TinkoPal.exe
AUTST|Zstb.exe
FILEN|zsearch.exe
FILEN|zstb.exe
FILEN|winupie.exe
FILEN|trustinpopups.exe
FILEN|%windir%\tvm_b5.exe
AUTST|djtopr1150.exe
FILEN|unibar.exe
FILEN|vsolutions.exe
FILEN|bi_prob.exe
FILEN|sysvx.exe
FILEN|%userprofile%\desktop\WeatherscopeSetup.exe
FILEN|weatherscope.exe
FILEN|weatherscopesetup.exe
FILEN|whagent.exe
FILEN|whagent_update.exe
FILEN|whcc-giant.exe
FILEN|whcc_realeuser.exe
FILEN|whinstaller.exe
FILEN|whsurvey.exe
FILEN|edowst3.exe
FILEN|zcwedowst3.exe
FILEN|websecurealert.exe
FILEN|websecurealertsetup.exe
FILEN|websecureuninstaller.exe
FILEN|vvsni_sync_webinst.exe
FILEN|vvsn.exe
FILEN|whse_pb.min.g2inst.exe
FILEN|vvsn_fanz0110inst.exe
AUTST|WhenUStart.exe
FILEN|vvsni_pbtb0100inst.exe
FILEN|saveinstcm.exe
FILEN|saveuninst.exe
FILEN|saveupdate.exe
FILEN|setupsavenow.exe
FILEN|vvsni_savenowsiteinst.exe
FILEN|setupweathercast.exe
FILEN|weatherinst.exe
FILEN|weirdontheweb_topc.exe
FILEN|mediaaccess.exe
FILEN|mediaacck.exe
FILEN|winad.exe
FILEN|winka.exe
FILEN|msupdater.exe
FILEN|mynexus.exe
FILEN|webnexus.exe
FILEN|wnad-update.exe
FILEN|wnad.exe
FILEN|bobsaver.exe
FILEN|popunder.exe
FILEN|xtcfgloader.exe
FILEN|xtcfgrunner.exe
FILEN|xupiterstartup.exe
FILEN|xupiterstartup2003.exe
FILEN|xupitertoolbarinstaller.exe
FILEN|xupitertoolbarloader.exe
FILEN|xupiterwauninstaller.exe
FILEN|best.exe
FILEN|yazzle1119oinuninstaller.exe
FILEN|yazzle1264oinadmin.exe
FILEN|yazzle1264oinuninstaller.exe
FILEN|yazzlebundle-1264.exe
AUTST|FT_SilentSudokuInstaller.exe
FILEN|ageu_silentsudokuinstaller.exe
FILEN|ageu_sudokuinstaller.exe
FILEN|ft_silentsudokuinstaller.exe
FILEN|gs_silentsudokuinstaller.exe
FILEN|yazzle1119oinadmin.exe
FILEN|yazzlebundle-1119.exe
FILEN|yazzlebundle-1304.exe
FILEN|yazzlebundle-1438.exe
FILEN|yazzlebundle-1452.exe
FILEN|waterfalls1awfree.exe
FILEN|yourscreen_4_pch.exe
FILEN|yoursitebar.exe
FILEN|adstartup.exe
FILEN|%programfiles%\zango\zango.exe
FILEN|zango.exe
FILEN|zangoinstaller.exe
FILEN|zangomuncher.exe
FILEN|zangotbuninstaller.exe
FILEN|jadeshadowinstall.exe
FILEN|jadeshadowsetup.exe
FILEN|zapspot.exe
FILEN|dwdsregt.exe
FILEN|zicorn001.exe
FILEN|icont.exe
FILEN|%windir%\system32\spiven.exe
FILEN|zipclix.exe
FILEN|axdlplug-1.5.0.0-0281-setup.exe
FILEN|axdlplug-1.5.0.0-147-setup.exe
FILEN|npdlplug-1.5.0.0-147-setup.exe
FILEN|%systemdrive%\msole32.exe
FILEN|opensite.exe
FILEN|absolu-trans.exe
REGKE|HKEY_CLASSES_ROOT\AppID\exengd.EXE
FILEN|int179663.exe
FILEN|gdnus208.exe
AUTST|addot.exe
FILEN|adult_chat.exe
FILEN|tibs3.exe
FILEN|dbn1742.exe
FILEN|%Windir%\system32\dsldbaccess.exe
FILEN|%Windir%\system32\Geaccess.exe
FILEN|2da45.exe
FILEN|beauty[schoenerwerden,1].exe
FILEN|cocktails[ccp-10097,de].exe
FILEN|gifsworld[gwd-10927,de].exe
FILEN|hausaufgaben[hun-10002,de].exe
FILEN|hausaufgaben[hun-10222,de].exe
FILEN|horoskop_erstellen[aie-10070,de].exe
FILEN|lehrstellen[lhs-10004,de].exe
FILEN|liebesbriefe[lbi-10023,de,start].exe
FILEN|pflanzen[pla-10006,de].exe
FILEN|routenplanerag.exe
FILEN|sagen.exe
FILEN|satanismus.exe
FILEN|satfrequenzen.exe
FILEN|scheisse[schei1,1].exe
FILEN|schulstadt-1.exe
FILEN|schulstadt-2.exe
FILEN|schulstadt-3.exe
FILEN|schulstadt-4.exe
FILEN|schulstadt-5.exe
FILEN|schulstadt-6.exe
FILEN|schulstadt-7.exe
FILEN|schulstadt.exe
FILEN|schwanger.exe
FILEN|setup(1-1md-0-0-,us)-1.exe
FILEN|sexworld[sexworld,1].exe
FILEN|sharing-ag-1.exe
FILEN|sharing-ag.exe
FILEN|slowenien.de.exe
FILEN|smiley[smileycastle,1].exe
FILEN|smiley[syc-10008,1].exe
FILEN|smilie-fabrik.exe
FILEN|sms-stadt-1.exe
FILEN|sms-stadt-2.exe
FILEN|sms-stadt-3.exe
FILEN|sms-stadt.exe
FILEN|sms-tool.exe
FILEN|songtexte[sgx-10001,1].exe
FILEN|songtextzone-1.exe
FILEN|songtextzone-2.exe
FILEN|songtextzone-4.exe
FILEN|spass4u[s4e-10020,1].exe
FILEN|spasspilot-1.exe
FILEN|spicktricks[ree-10323,de].exe
FILEN|spieledownload[ssg-10001,1,a63e].exe
FILEN|spieleindex[spieleindex,1].exe
FILEN|spiele_runterladen[geg-10066,1].exe
FILEN|sprueche.exe
FILEN|stammbaum.de.exe
FILEN|starfuck.exe
FILEN|stars-nackt.exe
FILEN|sternzeichen[szn-10011,de].exe
FILEN|straflos[anti-report,1].exe
FILEN|suchmaschinen-1.exe
FILEN|supergames[supergames,1].exe
FILEN|taroskop.exe
FILEN|tattoo-1.exe
FILEN|tattoo-2.exe
FILEN|tattoopalace-11.exe
FILEN|tattoos[tod-10109,de].exe
FILEN|tattoos[tod-10133,1].exe
FILEN|tattoovorlagen-de[toe-10362,1]-2.exe
FILEN|tattoo[tattoomania,1].exe
FILEN|tattoo[toe-10082,1].exe
FILEN|template-tempel.exe
FILEN|tests[iqwelt,1].exe
FILEN|test[teh-10116,de,start4].exe
FILEN|tierbabys[tierbabys,1].exe
FILEN|toprezept.exe
FILEN|trilian[trilian-de,1].exe
FILEN|tuerkei.exe
FILEN|turkgays[tks-10001,1].exe
FILEN|umsatzsteigern[uee-10001,1].exe
FILEN|valueradio-1.exe
FILEN|vornamen.exe
FILEN|vornamen[vnf-10049,1].exe
FILEN|vornamen[vnf-10103,1].exe
FILEN|wetter-basis-1.exe
FILEN|wetter-basis.exe
FILEN|witzealarm.exe
FILEN|witze[counterde,1].exe
FILEN|wohnung.exe
FILEN|maxd641.exe
FILEN|syslcznp.exe
AUTST|ciakaisen.exe
AUTST|lateshow.exe
AUTST|wke.exe
FILEN|%USERPROFILE%\Start Menu\messaggio3.exe
AUTST|sws.exe
FILEN|gd-ff_be.exe
FILEN|gd-ff_us.exe
FILEN|gdnca167.exe
FILEN|hacker spider.exe
FILEN|123-sexkino.exe
FILEN|aktgirls.exe
FILEN|aktshow.exe
FILEN|amateur-hardcore-sex.exe
FILEN|analorgasmus.exe
FILEN|analxxx.exe
FILEN|babesex.exe
FILEN|begleitung-online.exe
FILEN|berlin-erotik.exe
FILEN|betnaker.exe
FILEN|bigbusen.exe
FILEN|bumsmich.exe
FILEN|bundesligagirls.exe
FILEN|busencam.exe
FILEN|busenline.exe
FILEN|busenshow.exe
FILEN|busentreff.exe
FILEN|busenweb.exe
FILEN|camcontrol.exe
FILEN|casarossa.exe
FILEN|city-girls.exe
FILEN|clickfick.exe
FILEN|computersex.exe
FILEN|cyber-angels.exe
FILEN|cybererotiva.exe
FILEN|debabes.exe
FILEN|degirls.exe
FILEN|deutsch.exe
FILEN|devotelust.exe
FILEN|disnex.exe
FILEN|donnavargas.exe
FILEN|dream-sex.exe
FILEN|e-kontakte.exe
FILEN|ecsfun.exe
FILEN|ero-world.exe
FILEN|eroclick.exe
FILEN|eroklick.exe
FILEN|erophone.exe
FILEN|eroplanet.exe
FILEN|erotic-news.exe
FILEN|eroticenter.exe
FILEN|eroticliveshow.exe
FILEN|erotik-news.exe
FILEN|euromodels2.exe
FILEN|fickclick.exe
FILEN|fickenonline.exe
FILEN|fickklick.exe
FILEN|fickline.exe
FILEN|fickschule.exe
FILEN|ficksie.exe
FILEN|fussballgirls.exe
FILEN|germany.exe
FILEN|gina-wild-sex.exe
FILEN|girls.exe
FILEN|girlsbesuch.exe
FILEN|girlshotel.exe
FILEN|girlstalk.exe
FILEN|glas-haus.exe
FILEN|hardcore-live-sex.exe
FILEN|hooters.exe
FILEN|hotbunny.exe
FILEN|hotelbesuch.exe
FILEN|hotelgirls.exe
FILEN|hotpower.exe
FILEN|hotvot.exe
FILEN|hotwied.exe
FILEN|klickfick.exe
FILEN|kontaktechat.exe
FILEN|lesbenhaus.exe
FILEN|life-girl.exe
FILEN|lifegirl.exe
FILEN|live-studio.exe
FILEN|livechatcam.exe
FILEN|livephone.exe
FILEN|livesex.exe
FILEN|livesexkanal.exe
FILEN|liveshow.exe
FILEN|lovephone.exe
FILEN|lucky-punch.exe
FILEN|macronedia.exe
FILEN|maxxcafe.exe
FILEN|meetboys.exe
FILEN|meinecam.exe
FILEN|moesenhaus.exe
FILEN|mytits.exe
FILEN|nacktshow.exe
FILEN|nudeliveshow.exe
FILEN|online-begleitung.exe
FILEN|online-escort.exe
FILEN|orgasmusbilder.exe
FILEN|orgasmusline.exe
FILEN|orgasmuslive.exe
FILEN|orgasmusparty.exe
FILEN|orgasmusvideo.exe
FILEN|osnastrip.exe
FILEN|pagesex.exe
FILEN|pam.exe
FILEN|peep-show-girls.exe
FILEN|persiankitti.exe
FILEN|persianklitty.exe
FILEN|phonegirl.exe
FILEN|phythom.exe
FILEN|playboobs.exe
FILEN|playgal.exe
FILEN|playmoesen.exe
FILEN|playmuschi.exe
FILEN|porncam.exe
FILEN|porno-porno-sex-sex.exe
FILEN|pornodelux.exe
FILEN|pornomoesen.exe
FILEN|privatbesuch.exe
FILEN|pussygeil.exe
FILEN|pussyhaus.exe
FILEN|redlightgirls.exe
FILEN|rotlichtchat.exe
FILEN|rotlichtgirls.exe
FILEN|rotlichtline.exe
FILEN|rotlichtshow.exe
FILEN|schulsex.exe
FILEN|sex-erotik-show.exe
FILEN|sex-live-chat.exe
FILEN|sex-porno-show.exe
FILEN|sex-rooms.exe
FILEN|sex-sex-porno-porno.exe
FILEN|sex-sex-sex-pussy.exe
FILEN|sex-tabulos.exe
FILEN|sexcall.exe
FILEN|sexdominanz.exe
FILEN|sexevents.exe
FILEN|sexfetish.exe
FILEN|sexillusion.exe
FILEN|sexkarussell.exe
FILEN|sexkeller.exe
FILEN|sexme.exe
FILEN|sexmich.exe
FILEN|sexpicturegallery.exe
FILEN|sexroulette.exe
FILEN|sexschule.exe
FILEN|sextacy.exe
FILEN|sexycamera.exe
FILEN|smutlamd.exe
FILEN|soos.exe
FILEN|strapsshow.exe
FILEN|strichgirls.exe
FILEN|strip-eonline.exe
FILEN|strip-girls.exe
FILEN|stripcan.exe
FILEN|striplime.exe
FILEN|stripline.exe
FILEN|strippenonline.exe
FILEN|stripschule.exe
FILEN|studiosex.exe
FILEN|suendenspiele.exe
FILEN|teenmail.exe
FILEN|telestrip.exe
FILEN|the-sweets.exe
FILEN|tittengeil.exe
FILEN|tittenline.exe
FILEN|tittenseite.exe
FILEN|tittenspiele.exe
FILEN|tittenweb.exe
FILEN|tittenwelt.exe
FILEN|travelsex24.exe
FILEN|venusgirls.exe
FILEN|venusphone.exe
FILEN|victoriasecreet.exe
FILEN|videochatcam.exe
FILEN|viona.exe
FILEN|vollbusicam.exe
FILEN|wichsen.exe
FILEN|wild-sex.exe
FILEN|xxxphone.exe
FILEN|hotactiondating-uninstall.exe
FILEN|hotactiondating.exe
FILEN|nsi145.exe
FILEN|gratis-sex-crack.exe
FILEN|traumdate.exe
FILEN|iedisco.exe
FILEN|view_sex_now.exe
FILEN|net900.exe
FILEN|od-dflt0001.exe
FILEN|od-stnd191.exe
FILEN|%systemroot%\Orgasm.exe
FILEN|30500105.exe
FILEN|parisvoyeur.exe
FILEN|browser_plugin.exe
FILEN|hotsurprise_be.exe
FILEN|ukvideo2.exe
AUTST|bodr.exe
FILEN|britney spears nackt.exe
FILEN|hzs-10030.exe
FILEN|stripsetup.exe
FILEN|systemvxd.exe
FILEN|clbmn2.exe
FILEN|tibsloader.exe
FILEN|adult.exe
FILEN|cammaus.exe
FILEN|deutsche-peepshow.exe
FILEN|erotik-hotel.exe
FILEN|funland.exe
FILEN|lustmaus.exe
FILEN|megabusen.exe
FILEN|nutte.exe
FILEN|sabine.exe
FILEN|sabine2.exe
FILEN|sexstop.exe
FILEN|spanner.exe
FILEN|stchat.exe
FILEN|telefun.exe
FILEN|tscash.exe
FILEN|ueber40de.exe
FILEN|xxxlivesex.exe
FILEN|23aw0001.exe
FILEN|arr.exe
FILEN|belgium_sex-uninstall.exe
FILEN|crush.exe
FILEN|datemakerintl.exe
FILEN|direktsex.exe
FILEN|freesexx.exe
FILEN|go in.exe
FILEN|handy-paradies.exe
FILEN|hardcoreteens.exe
FILEN|hotsex.exe
FILEN|hotsexvideos.exe
FILEN|hot_canada.exe
FILEN|lolitasex.exe
FILEN|od-stnd24.exe
FILEN|piratos.exe
FILEN|pissing.avi.exe
FILEN|sexy-uninstall.exe
FILEN|sexy_belgium-uninstall.exe
AUTST|\windows\syswin.exe
FILEN|agrit.exe
FILEN|alberghi.exe
FILEN|qualsiasi.exe
FILEN|xxlav003.exe
FILEN|xdiver.exe
FILEN|xgenius.exe
FILEN|almaster.exe-34cdc7f0.pf
FILEN|backdoor.hacktack.110.exe
FILEN|backdoor.hacktack.112.exe
FILEN|backdoor.hacktack.120.b.exe
FILEN|backdoor.hacktack.exe
AUTST|djebmm350.exe
FILEN|disp350.exe
FILEN|ebatesmoemoneymaker.exe
FILEN|ebatesmoemoneymaker1.exe
FILEN|websavingsfromebates.exe
FILEN|websavingsfromebates0.exe
FILEN|disp1150.exe
FILEN|sahagent-seedcorn1002.exe
FILEN|w11150.exe
FILEN|webrebates.exe
FILEN|webrebates0.exe
FILEN|webrebates1.exe
FILEN|webrebates2.exe
FILEN|webrebatesrun.exe
FILEN|webrebates_auto_installsilent.exe
FILEN|alexainstaller.exe
FILEN|mksc.exe
FILEN|ossproxy.exe
FILEN|rlvknlg.exe
FILEN|nhupdater.exe
FILEN|http-tunnelclient.exe
FILEN|httptunnelinstallerv403065.exe
AUTST|AdArmor.exe Monitor
FILEN|adarmor.exe
FILEN|adarmorinstaller.exe
FILEN|adarmor_monitor.exe
FILEN|adarmor_updater.exe
FILEN|ads adware remover.exe
FILEN|adsremover.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\alertSpy.exe
FILEN|alertspy.exe
FILEN|alfacleaner.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiVerminser.exe\
FILEN|antiverminser.exe
FILEN|av_setup.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusProtection.exe
FILEN|antivirusprotection.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusSolution.exe
FILEN|antivirussolution.exe
FILEN|antivirus_solution_setup_1.0.0.exe
FILEN|bravesentry.exe
FILEN|bravesentrysetup.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ad-protect.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ContraVirus.exe
FILEN|%temp%\ContraVirus 2.0 Installer.exe
FILEN|contravirus.exe
FILEN|contraviruspro.exe
FILEN|cv_1_setup.exe
FILEN|xpuupdate.exe
FILEN|%allusersprofile%\Start Menu\Programs\Startup\Start CurePCSolution.exe.lnk
FILEN|curepcsolution.exe
FILEN|udc2006.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ExpertAntivirus.exe
CLASS|ad-protect.EXE
FILEN|expertantivirus.exe
AUTST|FixerAntispy.exe Monitor
FILEN|fixerantispy.exe
FILEN|fixerantispyinstaller.exe
FILEN|fixerantispy_monitor.exe
FILEN|fixerantispy_updater.exe
FILEN|killandclean.exe
FILEN|killandcleansetup.exe
FILEN|killandcleanupdate.exe
FILEN|malwarestopper.exe
FILEN|malwarestoppersetup.exe
FILEN|isec30.exe
FILEN|perfectcleaner.exe
FILEN|perfectcleaner_setup.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Pestbot.exe
FILEN|pestbot.exe
FILEN|pestcapture.exe
FILEN|pestcapturesetup.exe
FILEN|regfreeze.exe
REGKE|HKEY_CLASSES_ROOT\AppID\ad-protect.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Spy-Shield.exe
FILEN|spyaway.exe
FILEN|spyaway_setup.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\SpyAxe.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\spyaxe.exe
FILEN|spycrush.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyDawn.exe
FILEN|spydawn.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyFalcon.exe
FILEN|atmclk.exe
FILEN|spyfalcon.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHazard.exe
FILEN|spyhazard.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHeal.exe
FILEN|spymarshal.exe
FILEN|spysoldier.exe
FILEN|spysoldier_setup.exe
FILEN|spyvampire.exe
FILEN|spyvampire_1.0.1.311_install.exe
FILEN|%userprofile%\Desktop\SCFree.exe
FILEN|%userprofile%\SCFree.exe
FILEN|spyclean.exe
FILEN|spywinclean.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareQuake.exe
FILEN|%WINDir%\system32\atmclk.exe
FILEN|%WINDir%\system32\dcomcfg.exe
FILEN|spy-quake2.exe
FILEN|%temp%\NSIS_SpywareSecure_trial_setup.exe
FILEN|spyware-secure_trial.exe
FILEN|spywaresecure_trial_setup.exe
FILEN|slimshieldinstall.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareLocked 3.5.exe
FILEN|spywarelocked 3.5.exe
FILEN|spywarelocked.exe
FILEN|spysheriff.exe
FILEN|spywarestrike.exe
FILEN|ss_setup.exe
FILEN|%windir%\SGPro.exe
FILEN|sgpro.exe
FILEN|sg_free.exe
FILEN|%windir%\downloaded program files\usdr6_0001_d08m0404netinstaller.exe
FILEN|sd2006.exe
FILEN|systemdoctor2006freeinstall.exe
FILEN|systemdoctorfreesetup.exe
AUTST|a856cdb1.exe
FILEN|bundleouter2601031121.exe
FILEN|vb2uninstaller4_19.exe
FILEN|vbouncerinner.exe
FILEN|vbouncerinner1007.exe
FILEN|vbouncerinner1106.exe
FILEN|vbouncerinner1107.exe
FILEN|vbouncerinner1108.exe
FILEN|vbouncerinner1109.exe
FILEN|vbouncerouter1123030429.exe
FILEN|vbouncerouter1203.exe
FILEN|virtualbouncer.exe
FILEN|virtual_bouncer.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\virus-bursters.exe\
FILEN|vb_distrib.exe
FILEN|virus-bursters.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\VirusProtectPro 3.4.exe 3.4
FILEN|VirusProtectPro 3.4.exe
AUTST|hclean32.exe
FILEN|wareoutupdate.exe
AUTST|fat.exe
FILEN|%USERPROFILE%\desktop\WinFixerScannerInstall.exe
FILEN|wfx5.exe
FILEN|winfixer2005trialsetup.exe
FILEN|%userprofile%\Desktop\WinHoundinstaller.exe
FILEN|%windir%\WinHoundInstaller.exe
FILEN|winhound.exe
FILEN|worldantispy.exe
FILEN|evcztdq_pinch.exe
FILEN|qmtsfzh_pinch.exe
Raw Strings:
--------------------------------------------------
FILEN|surfairypp.dll
FILEN|surfairys.exe
NEWPR|1128|SurfSideKick
PRCAT|5
CLSID|{000ab005-ff12-42c2-8df5-39e12e5f9c91}
CLSID|{02ee5b04-f144-47bb-83fb-a60bd91b74a9}
CLSID|{4a2283c2-4d10-4954-1bbc-b730a621813c}
CLSID|{ca0e28fa-1afd-4c21-a8dc-70eb5be2f076}
CLSID|{fa89e1b0-e902-6968-bea5-156ab2fc177b}
DIREC|%CommonProgramFiles%\vcclient\
DIREC|%ProgramFiles%\SurfSideKick 2\
DIREC|%ProgramFiles%\SurfSideKick 3\
DIREC|%programfiles%\SurfSideKick\
AUTST|cashplusmedia.exe
AUTST|cyshgd
AUTST|dB2qRTc5T
AUTST|DNS
AUTST|Ebwh
AUTST|ezisde
AUTST|GsAds
AUTST|kpfbph
AUTST|KwtFRTc2W
AUTST|lfecqh
AUTST|lqxcx
AUTST|MedGS
AUTST|mqwf
AUTST|mtzfcv
AUTST|opr
AUTST|pstdae
AUTST|qppxjf
AUTST|Qwnoyep
AUTST|SurfSideKick
AUTST|SurfSideKick 2
AUTST|SurfSideKick 3
AUTST|Windows Incontext
AUTST|xeqdnc
RKSOF|SurfSideKick
RKSOF|SurfSideKick2
RKSOF|SurfSideKick3
UINST|Surf SideKick
UINST|Surf Sidekick_is1
FILEN|repairs303169536.dll
FILEN|repairs303169590.dll
FILEN|ssk.exe
FILEN|ssk3repairinstall.exe
FILEN|ssk3_b5 seedcorn 4.exe
FILEN|sskbho.dll
FILEN|sskcore.dll
FILEN|sskcwrd.dll
FILEN|sskffcore.dll
FILEN|sskknwrd.dll
FILEN|sskuknwrd.dll
FILEN|surfsidekick.exe
NEWPR|2487|SweetBar
PRCAT|5
CLSID|{21ba3ee1-ccc9-4381-9997-928127b0c2d6}
CLSID|{68a7f9fa-a202-4d45-aaba-a10dcac0d899}
DIREC|%AllUsersProfile%\Start Menu\Programs\SweetBox\
DIREC|%ProgramFiles%\SweetBox\
AUTST|SweetBox
CLASS|SweetBox.SweetActive
RKSOF|SweetBar
SERVK|IPRIP
NEWPR|1697|SwimSuitNetwork
PRCAT|5
AUTST|swimsuitnetwork
NEWPR|979|SyncroAd
PRCAT|5
DIREC|%programfiles%\Windows SyncroAd
AUTST|Windows SyncroAd
UINST|Windows SyncroAd
FILEN|%SystemRoot%\System32\ide21201.vxd
FILEN|syncroad.exe
NEWPR|730|Syscpy
PRCAT|5
NEWPR|2465|System Process
PRCAT|5
CLSID|{2588bbaa-f6c6-0053-c746-05ce98d3d296}
CLSID|{465f66ce-d075-cca7-7426-098c0e74be6d}
CLSID|{49ae83eb-5b19-7104-6a65-0b52de3de139}
CLSID|{5064a992-9575-e73c-c514-0a4cb0eb764c}
CLSID|{688b592e-4ab8-49a6-f9b2-02b3db5f7b0a}
CLSIA|{9bb5b49c-0d59-418d-a6a5-f6373b8fef64}
CLSID|{c2eeb4fa-b6d6-41b9-9cfa-aba87f862bcb}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , *.system-processes
DIREC|%ProgramFiles%\BHO Plugin\
RKSOF|BHO
RKSOF|BHO\icons
RKSOF|System Process
UINST|Startup
SERVK|TCP and UDP Support
NEWPR|1168|System Soap Pro
PRCAT|5
AUTST|%ProgramFiles%\System Soap Pro
AUTST|System Soap Pro
RKSOF|system soap
UINST|System Soap Pro 3.2-AC1
NEWPR|1813|System61
PRCAT|5
CLSID|{c7967580-5f17-11d4-aac2-0000b4936e0c}
NEWPR|2785|TagAsaurus
PRCAT|5
DIREC|%programfiles%\Tagasaurus\
AUTST|TagASaurus
AUTST|win32094-86623726
FILEN|tagasaurus.exe
FILEN|tagasuarus97.exe
NEWPR|1914|TargetSavers
PRCAT|5
DIREC|%CommonProgramFiles%\ffor\
DIREC|%CommonProgramFiles%\tsa\
DIREC|%windir%\ffor\
AUTST|ffor
RKSOF|ffor
RKSOF|fqmq
RKSOF|mrqf
RKSOF|TSA
UINST|TSA
UINST|TSAUNINST
UINST|TSL Installer
FILEN|133_funtarget_4_0_4_0.exe
FILEN|tsinstall_4_0_3_8_b17.exe
FILEN|tsinstall_4_0_4_0_b4.exe
NEWPR|1701|Tatss
PRCAT|5
NEWPR|627|Tellafriend
PRCAT|5
CLSID|{5297e905-1dfb-4a9c-9871-a4f95fd58945}
CLSIA|{72a58725-2635-4725-8c53-676dfd1feb8d}
CLSID|{95b92d92-8b7d-4a19-a3f1-43113b4dbcaf}
RKSOF|zeropopup
FILEN|zp.cab
NEWPR|1703|TestTimer
PRCAT|5
FILEN|%systemroot%syssfitb.exe
NEWPR|424|TGDC
PRCAT|5
CLSIA|{05bbb56a-2a69-4a5c-bfda-43295dd67434}
AUTST|TGDC IE Plugin
FILEN|tgdc.exe
NEWPR|776|The Search Accelerator
PRCAT|5
CLSID|{3131a8d2-d92c-48ba-96ac-8a77d6a1d573}
CLSID|{33740aeb-2856-4004-b84b-37e2c0d4f13d}
CLSID|{44be0690-5429-47f0-85bb-3ffd8020233e}
CLSIA|{53cbee82-d747-11d3-9ed0-005004189684}
CLSIA|{607df741-7d0a-11d4-9edc-005004189684}
CLSID|{aae89d95-75cc-4708-87e5-60cf917b7b5b}
CLSIA|{ed8db0fd-d8f4-4b2c-bb5b-9ef040fe104d}
REGKE|HKEY_CURRENT_USER\Software\Maxthon\Plugin\toolbar\{44BE0690-5429-47f0-85BB-3FFD8020233E}
DIREC|%ProgramFiles%\TheSearchAccelerator\
DIREC|%programfiles%\UCmore\
DIREC|%userprofile%\Start Menu\Programs\UCmore - The Search Accelerator\
RKSOF|Effective-i
RKSOF|ucmore
RKSOF|UCmore.UcmoreTsaApp
UINST|UCmore - The Search Accelerator
FILEN|ucmie.dll
FILEN|ucmoreiex.exe
FILEN|ucmtsaie.dll
NEWPR|3046|Themexp
PRCAT|5
UINST|Themexp.org File
NEWPR|3161|Think-Adz
PRCAT|5
UINST|Enhanced Ads by Think-Adz
UINST|Think-Adz Search Assistant
NEWPR|2232|TinkoPal
PRCAT|5
DIREC|%ProgramFiles%\TinkoPal
DIREC|%USERPROFILE%\Start Menu\Programs\TinkoPal
RKSOF|Microsoft\Windows\CurrentVersion\App Paths\TinkoPal.exe
RKSOF|TinkoPal.exe
UINST|TinkoPal
FILEN|%USERPROFILE%\Desktop\TinkoPal.lnk
NEWPR|496|TinyBar
PRCAT|5
CLSIA|{69555be2-9a78-11d2-ba91-00600827878d}
CLSIA|{82599e0a-8c81-11d7-9f97-0050fc5441cb}
CLSIA|{8fb0f3e2-5193-11d7-9f88-0050fc5441cb}
NEWPR|2235|ToolBar.SBSoft.h
PRCAT|5
CLSIA|{bf8e8df4-fae4-4df4-acc0-d25ec1010714}
CLASS|TORUTORUX.ToruToruXCtrl
NEWPR|681|ToolbarCC
PRCAT|5
CLSIA|{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffa2}
CLSIA|{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffa6}
CLSIA|{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffa7}
CLSIA|{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffa8}
NEWPR|1258|ToonComics
PRCAT|5
AUTST|fqdin
AUTST|iedll
NEWPR|2516|Top20results
PRCAT|5
NEWPR|2645|Topfive searchAssistant
PRCAT|5
DIREC|%ProgramFiles%\TopSearch\
AUTST|TopSearch
RKSOF|TopMoxie\TopSearch
UINST|TopSearch
NEWPR|613|TOPicks
PRCAT|5
CLSID|{02cdb0ed-874a-4dcb-8d9f-c2e3b169f265}
CLSIA|{0352960f-47be-11d5-ab93-00d0b760b4eb}
CLSID|{16097036-894c-4c00-a61f-93ca0d49a70e}
CLSIA|{1717a4a5-d63a-4f70-b373-ae4aa46d1236}
CLSID|{1b540d44-3f61-4394-ae30-25fdc3649405}
CLSID|{1d3bce37-7834-4579-8169-e67681420a98}
CLSID|{258a3625-183b-4477-aee2-ea54df6d878d}
CLSID|{29e825aa-13bc-457c-806a-d72e4a25b3c5}
CLSID|{2ed5af98-9258-45ba-b79b-06625c92f662}
CLSID|{5c40012e-44ca-11d7-8411-0002a5f9d08e}
CLSID|{700dc0dd-f409-42e0-9de5-21ee1a2ba9fd}
CLSID|{80e81a0e-9741-4fbc-8ee3-3b78c04ada1d}
CLSID|{91d91d21-8008-429d-821c-7266aac84a9f}
CLSID|{9a7cfeda-5911-4ef1-b49a-35c34230ffc1}
CLSID|{9bbcf06c-dcd7-495d-80df-cdd5399d0ff8}
CLSID|{9d4548ce-92fd-4c6c-ae7f-3dbe3bc763d8}
CLSID|{9f8ac164-6826-4b52-8f65-9c31305e81cc}
CLSID|{ad5bc1f0-72d8-44b3-8e3d-8e8fecce43fb}
CLSID|{be7613d4-7d09-4cf8-b747-6dff0564891e}
CLSID|{ce9b37ec-d243-47a2-83db-3a8350175193}
CLSID|{d273d427-57c6-4b12-860f-bbb8195f6e2a}
CLSID|{d7cb5baf-18d9-46d4-8f72-909d409506fa}
CLSID|{e79dadc6-18d0-4a2a-831f-d196d41f8438}
CLSID|{fd42f6d3-7ab1-470c-979b-7996edc99099}
AUTST|topicks starter
CLASS|HtCheck2.CheckPage
CLASS|HtChe
ck2.CHelpObj
CLASS|IdiumUpdater.IdiumSysUpdater
CLASS|ToPicksReg.ToPickReg1
NEWPR|1806|TopSurfer
PRCAT|5
CLSID|{af657644-964c-4348-a8ad-72524b3a3ff1}
NEWPR|763|TotalVelocity zSearch
PRCAT|5
CLSID|{5886a6dc-aaf4-45e9-979a-8e5e6dee30e7}
CLSIA|{828a9ed2-c5bb-4caa-bcb7-a4cc024aafd6}
DIREC|%ProgramFiles%\zSearch\
AUTST|zSearch
AUTST|Zstb.exe
UINST|zSearch_is1
FILEN|zsearch.dll
FILEN|zsearch.exe
FILEN|zstb.exe
NEWPR|1706|Townews
PRCAT|5
CLSID|{634efde4-087d-4ce9-952f-63c9eeb2e0bf}
NEWPR|565|TradeExit
PRCAT|5
CLSIA|{f0230524-9d39-4e84-8452-41c592961ea7}
FILEN|winupie.exe
NEWPR|2627|Transponder.kz515
PRCAT|5
CLSID|{c0322f4c-ab89-4c3b-94ae-56de8a4bd07d}
CLSID|{ed1282a6-4a6e-4893-85fc-6ccfd39d8377}
CLASS|kz515Dll.kz515DllObj
RKSOF|kz515
NEWPR|2372|Trojan.Zlob.E
PRCAT|5
CLSID|{1ca480cd-c0e5-4548-874e-b85b17905b3a}
CLSID|{724510c3-f3c8-4fb7-879a-d99f29008a2f}
CLSID|{7caf96a2-c556-460a-988e-76fc7895d284}
FILEN|%windir%\ncompat.tlb
FILEN|%windir%\system32\msvol.tlb
NEWPR|2814|TrustIn Bar
PRCAT|5
CLSID|{07a78aea-4a54-4967-9a60-4b68592d30c7}
CLSID|{23cb9697-2835-45c5-8949-8a4e73aa70d4}
CLSIA|{590ffb84-6a29-4797-9c0e-b15df2c4cdcb}
CLSID|{9b053e00-78d3-47ae-b763-60ff36ff2886}
CLSID|{fe6c16c4-16ad-47b6-b250-26ad1829e49a}
DIREC|%ProgramFiles%\TrustIn Bar
DIREC|%ProgramFiles%\TrustIn Contextual
DIREC|%ProgramFiles%\TrustIn Search
CLASS|InetLoader.WeeklyExecuter
CLASS|Se_spoof.SpoofBHO
CLASS|ticont.MyBHO
CLASS|tisa.MyBHO
CLASS|TrustIn.activator
CLASS|TrustIn.StockBar
CLASS|TrustInContext.ContextualAds
RKSOF|TrustIn
RKSOF|TrustIn Bar
UINST|Contextual Ads
UINST|TICONT
UINST|TISA
UINST|TrustIn Bar
NEWPR|2942|Trustin popups
PRCAT|5
DIREC|%programfiles%\TrustIn Popups\
AUTST|TrustIn Popups
RKSOF|TrustIn Popups
UINST|TrustIn Popups
FILEN|trustinpopups.exe
NEWPR|1352|Trustyfiles
PRCAT|5
DIREC|%ALLUSERSPROFILE%\TrustyFiles
DIREC|%programfiles%\TrustyFiles
RKSOF|TrustyFiles
UINST|TrustyFiles
FILEN|%USERPROFILE%\Desktop\TrustyFiles Downloads and Sharing.lnk
FILEN|%USERPROFILE%\Desktop\TrustyFiles.lnk
NEWPR|2635|TrustyHound
PRCAT|5
CLSID|{aa2ad390-5ec0-4742-a5f6-a59b50fbdaa0}
DIREC|%AllUsersProfile%\Start Menu\Programs\TrustyHound-TS\
DIREC|%ProgramFiles%\TrustyHound-TB\
DIREC|%ProgramFiles%\TrustyHound-TS\
AUTST|TrustyHound-TS
CLASS|ToolBand.XBTP01786
CLASS|XBTB01786.IEToolbar
CLASS|XBTB01786.XBTB01786
RKSOF|XBTB01786
UINST|TrustyHound-TS ( Companion Tools )_is1
UINST|XBTB01786.XBTB01786Toolbar
FILEN|%USERPROFILE%\Desktop\CardFountain Greetings.lnk
FILEN|%USERPROFILE%\Desktop\Free Stuff Directory.lnk
FILEN|%USERPROFILE%\Desktop\FunFlirts Online Dating.lnk
FILEN|%USERPROFILE%\Desktop\TrustyHound Image Search.lnk
FILEN|%USERPROFILE%\Desktop\TrustyHound Web Search.lnk
NEWPR|1086|TryToFind
PRCAT|5
CLSIA|{90baeb8b-47c2-44b4-a5a6-b99d34f1d4c5}
CLSIA|{d8c6179a-58c3-4662-800a-22dae7dcb152}
DIREC|%ProgramFiles%\Try2Find\
CLASS|sptbax.Install
RKSOF|Try2Find
NEWPR|1232|TurboDownload
PRCAT|5
CLSID|{120e090d-9136-4b78-8258-f0b44b4bd2ac}
CLSID|{1a00c40b-da85-4aa3-a67f-582d9347eecd}
DIREC|%programfiles%\Maxspeed
AUTST|IEDriver
RKSOF|MaxSpeed
RKSOF|turbodownload
NEWPR|521|TV Media Display
PRCAT|5
CLSID|{20ec3d2d-33c1-4c9d-bc37-c2d500688da2}
CLSID|{707e6f76-9ffb-4920-a976-ea101271bc25}
CLSID|{965a592f-8efa-4250-8630-7960230792f1}
DIREC|%ProgramFiles%\TV Media\
AUTST|TV Media
AUTST|TVMD
AUTST|winpoet
UINST|tv media
FILEN|%windir%\tvm_b5.exe
FILEN|tvmbho.dll
FILEN|tvmcore.dll
FILEN|tvmcwrd.dll
FILEN|tvmknwrd.dll
NEWPR|650|Twain-Tech
PRCAT|5
CLSID|{000020dd-c72e-4113-af77-dd56626c6c42}
CLSID|{0000607d-d204-42c7-8e46-216055bf9918}
AUTST|alchem
AUTST|djtopr1150.exe
AUTST|odurhdvxjj
AUTST|xgn
CLASS|Twaintec.TwaintecObj
CLASS|TwaintecDll.TwaintecDllObj
FILEN|mxtarget.dll
FILEN|twaintec.dll
NEWPR|2317|TX4
PRCAT|5
NEWPR|722|UCSearch
PRCAT|5
CLSID|{0ff7dbe0-ce7d-43b2-b016-50f1c88551e5}
CLSID|{1cbf31fc-3c23-4ba6-af16-2cec501bd837}
CLSIA|{1fdec088-a699-46fe-bf76-d5fd6dae6150}
CLSID|{4c33d68d-9703-4636-b433-383d42d0847c}
CLSID|{737263fd-a882-4957-8136-c0fd923ff150}
CLSID|{bbbe1c1a-89f7-4af6-abd1-f8fbcfa47408}
CLSIA|{e62a47d8-74b1-4a93-963a-e5e43b7cc5c2}
DIREC|%ProgramFiles%\open site\
CLASS|UCSearch.ucUCSearch
NEWPR|2666|Ultrabar
PRCAT|5
CLSID|{57a157fe-f766-46f1-8eb5-4a48be2f5daf}
CLSID|{a735e796-6ed4-4987-80e5-15b74020d978}
DIREC|%ProgramFiles%\UltraBar\
UINST|UltraBar
FILEN|%WINDIR%\Downloaded Program Files\ultrabar.inf
NEWPR|2011|Unclassified
PRCAT|5
NEWPR|3332|Unibar
PRCAT|5
CLSID|{0bbf1c37-f268-4489-8b0d-4e03f37a8dbf}
CLSID|{3221a442-e009-47f6-97c8-835462acc6b2}
CLSID|{77519220-81b7-4eff-9d40-5bc7425d4e5b}
CLSID|{841b2b65-118d-4ff2-ad63-4cff44b8b68f}
CLSID|{dbaed463-f7c8-4046-90ad-bef771cad496}
CLSID|{dfcb34b6-902d-426e-ae2b-1b294ae19f4f}
CLSID|{fd5ec997-35ab-49b6-a504-d0879643845f}
DIREC|%programfiles%\unibar\
CLASS|KWBand.CExplorerBar
CLASS|KWBand.KeyWordBand
UINST|21805fef
UINST|38616223
UINST|6fe46231
FILEN|unibar.exe
NEWPR|2099|UpSpiral Toolbar
PRCAT|5
CLSID|{4e7bd74f-2b8d-469e-deff-ed65a486aa28}
DIREC|%ProgramFiles%\Upspiral Toolbar\
CLASS|upspiral.UPSPIRAL
CLASS|upspiral.UPSPIRALMenu Button
CLASS|upspiral.UPSPIRALToggle Button
RKSOF|Upspiral Toolbar
UINST|Upspiral
NEWPR|743|URLBlaze
PRCAT|5
CLSIA|{9feffbde-fe2f-4756-b4a7-90d976255f9b}
CLSIA|{ce7c3cf0-4b15-11d1-abed-709549c10000}
DIREC|%programfiles%\urlblaze
DIREC|%USERPROFILE%\Start Menu\Programs\URLBlaze\
DIREC|%windir%\System32\IEDriver\
UINST|DMVLite
UINST|URLBlaze
FILEN|%SystemRoot%\uburl.dat
FILEN|%USERPROFILE%\Desktop\URLBlaze.lnk
NEWPR|742|Verticity
PRCAT|5
NEWPR|2614|VideoC
PRCAT|5
CLSID|{58dbce03-ffc3-4452-ab1d-c19ee9825a50}
NEWPR|1698|Viewpoint Media Toolbar
PRCAT|5
CLSID|{a7327c09-b521-4edb-8509-7d2660c9ec98}
CLSID|{f8ad5aa5-d966-4667-9daf-2561d68b2012}
DIREC|%allusersprofile%\Application Data\Viewpoint\ViewBar\
DIREC|%appdata%\Viewpoint\ViewBar\
DIREC|%programfiles%\Viewpoint\Viewpoint Toolbar\
CLASS|ViewBar.ViewBar
CLASS|ViewBarBHO.BHO
RKSOF|Viewpoint\ViewpointSearchBar
UINST|Viewpoint Manager
UINST|ViewpointSearchBar
NEWPR|2138|VipSearcher
PRCAT|5
CLSID|{0393fe81-0bbd-4bce-b4f2-c643aa7d77dd}
CLSID|{10bc40b5-5019-4a47-b033-308ca16d4959}
CLSID|{1559c6fd-8bde-476e-98c7-871e59193fce}
CLSID|{405132a4-5dd1-4ba8-a181-95c8d435093a}
CLSID|{c2e07b68-2f46-4dbb-8261-285794b7f8de}
NEWPR|1707|VirtuMonde
PRCAT|5
CLSID|{13589181-4f0d-4553-b9f8-b4b72172c139}
CLSID|{18722863-6d1d-4300-bf29-406948eda7cb}
CLSID|{30279f2d-1a38-4785-97d4-5c3508bdb289}
CLSID|{3ec8e271-fab9-418a-8a8e-65aeb4029e64}
CLSID|{446cf8a5-617e-4d91-95ae-ae78ce0d06af}
CLSID|{44e5b409-35a2-4e8d-bf94-344222323a53}
CLSID|{55e301e5-ba44-4095-bb0b-14e0123ccf71}
CLSID|{60112085-e1ce-4e0e-823a-ebb1ad98804c}
CLSID|{68132581-10f2-416e-b188-4e648075325a}
CLSID|{69eab151-c904-4734-aa74-a952290c5387}
CLSID|{6a06cdad-9d2d-42a0-9c91-c0cf7cb9971b}
CLSID|{6d33b121-5c4c-4450-9d1f-7b67085cc199}
CLSID|{72ac6865-b1d3-4c32-a27b-4b3bf04de655}
CLSID|{73529697-d46a-4f7d-8a93-01378fcaeda4}
CLSID|{77849d67-5672-4b68-93e2-cceff1e3949e}
CLSID|{8109af33-6949-4833-8881-43dcc232b7b2}
CLSID|{870b70d4-f6da-47ae-9158-d146440a0a4d}
CLSID|{bf755b85-ea69-4f58-9a59-d85f384a15ff}
CLSID|{c69fa570-7fde-4c49-a7bc-cb1cf24be66b}
CLSID|{d38439ec-4a7f-42b4-90c2-d810d7778fdd}
CLSID|{d6964fd8-3af1-4a2a-abb7-3d0c62924fd6}
CLSID|{d9511bf5-3c27-40ac-96da-2f439720efec}
CLSID|{df57feb6-9bce-45e3-aa65-be327b8cce7f}
CLSID|{ed5abc42-8e4f-4c39-9972-f0cf619d672f}
CLSID|{f32f8ecd-6cf3-459d-82f2-9738392c85a8}
CLSID|{fc148228-87e1-4d00-ac06-58dcaa52a4d1}
CLSID|{fd8609ec-7d7c-4778-ab8f-0053245550ef}
CLSID|{ff31c059-428b-4f07-bd1b-8f5dad170182}
AUTST|*catw
AUTST|ddayv
AUTST|pmnkk
AUTST|pmnlj
AUTST|windowsupd
FILEN|%systemroot%\system32\cbxwx.dll
NEWPR|2580|Virutek
PRCAT|5
AUTST|smsys
NEWPR|1811|Vividence Connector
PRCAT|5
CLSID|{c3bcc488-1ae7-11d4-ab82-0010a4ec2338}
NEWPR|2865|VMCleaner
PRCAT|5
NEWPR|2236|VoiceIP
PRCAT|5
REGKE|HKEY_CURRENT_USER\Software\VoiceIP
CLASS|VoiceIPDll.VoiceIPDllObj
NEWPR|912|Voonda Toolbar
PRCAT|5
CLSIA|{4e7bd74f-2b8d-469e-d4ff-eb2cf4d5fa7d}
NEWPR|1274|VroomSearch
PRCAT|5
CLSIA|{dab941d8-bc94-4819-ab4d-5598c65fa3fe}
CLSID|{f0c08b30-ba30-4feb-924b-2e250cf0697d}
AUTST|Tsa2
AUTST|Tsl2
NEWPR|3440|VSToolbar
PRCAT|5
CLSID|{74dd705d-6834-439c-a735-a6dbe2677452}
CLSID|{7addcf69-1cd5-4a57-8055-bb955805d918}
DIREC|%programfiles%\VSToolbar\
DIREC|%userprofile%\Local Settings\Application Data\VSolutions\
RKSOF|VSolutions
UINST|VSolutions Toolbar
FILEN|vsadd-in.dll
FILEN|vsolutions.exe
NEWPR|25|VX2
PRCAT|5
CLSID|{00000000-59d4-4008-9058-080011001200}
CLSIA|{00000000-5eb9-11d5-9d45-009027c14662}
CLSID|{00000026-8735-428d-b81f-dd098223b25f}
CLSID|{0000005d-c175-4405-bac5-1f3b2baf67c6}
CLSID|{00000062-2e5f-4af7-986e-5b64e0951a96}
CLSID|{00000097-7c67-4ba6-8b42-05128941688a}
CLSID|{0000026a-8230-4dd4-be4f-6889d1e74167}
CLSIA|{00000580-c637-11d5-831c-00105ad6acf0}
CLSID|{2cfb0ffd-a768-41d3-9b2d-059b80d03610}
CLSIA|{4cbbc676-507f-11d0-b98b-000000000000}
CLSID|{7632373d-4438-4d36-be59-22dc4dd85f41}
CLSIA|{a1a961da-2ba6-4032-859e-01ac35357163}
CLSIA|{ffd2825e-0785-40c5-9a41-518f53a8261
AUTST|Belt
AUTST|kkqejwjaqtb
AUTST|ntechin
AUTST|popuppers64
AUTST|satmat
AUTST|SysStart
AUTST|xqkako
AUTST|ZStart
CLASS|SiteHlpr.SiteHlprObj
CLASS|VX2.VX2Obj
RKSOF|TPS108
FILEN|%systemroot%\system32\vx0.nls
FILEN|%systemroot%\system32\vx1.nls
FILEN|%systemroot%\system32\vx1x.nls
FILEN|%systemroot%\system32\vx2.nls
FILEN|%systemroot%\system32\vx2x.nls
FILEN|%systemroot%\system32\vx3.nls
FILEN|%systemroot%\vx0.nls
FILEN|bi_prob.exe
FILEN|msview.dll
FILEN|sysvx.exe
FILEN|tps108.cab
FILEN|tps108.dll
FILEN|vx2.dll
NEWPR|630|W32.Hawawi.Worm
PRCAT|5
CLSID|{3df2ae33-26a8-11d4-bdd2-00104bfec09f}
CLASS|smtpcontrol.smtp
NEWPR|484|Wazam
PRCAT|5
CLSIA|{b5e60a66-0c51-4894-8df8-cbdf4e478d58}
NEWPR|898|WeatherScope
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Weatherscope
DIREC|%ProgramFiles%\Weatherscope
RKSOF|Gator.com\Gator\dyn\GCH\_weather
RKSOF|Gator.com\Weatherscope
RKSOF|Weatherscope
UINST|Weatherscope
FILEN|%userprofile%\desktop\WeatherscopeSetup.exe
FILEN|weatherscope website.lnk
FILEN|weatherscope.exe
FILEN|weatherscopesetup.exe
NEWPR|634|Web behavior
PRCAT|5
CLSIA|{0054ad19-7e4e-4ae4-b275-20f237280f5c}
CLSIA|{645d793b-33e2-4175-a7e1-ba490839358a}
NEWPR|1237|Web3000
PRCAT|5
AUTST|w3knetwork
RKSOF|web3000.com
UINST|textwiz_is1
UINST|web3000 network
UINST|xtractor plus_is1
NEWPR|2525|WebBullion
PRCAT|5
RKSOF|VB and VBA Program Settings\webbullion
NEWPR|2134|Webcrawler
PRCAT|5
CLSID|{9677f3f1-e994-451f-805f-7148cc8ae040}
NEWPR|2517|WebDir
PRCAT|5
CLSID|{453dca38-2a09-4dbe-a617-a2711c8480d0}
CLSID|{c003c49f-53e4-4a72-b7d6-0b2b9997392f}
CLSID|{e7bf2c44-c0cc-4592-8349-0f899ada5447}
REGKE|HKEY_CLASSES_ROOT\AppID\webdir.DLL
CLASS|webdir.WebDirObj
NEWPR|26|WebHancer
PRCAT|5
CLSID|{c89435b0-cdfe-11d3-976a-00e02913a9e0}
CLSID|{c8cb3870-cdfe-11d3-976a-00e02913a9e0}
CLSID|{c900b400-cdfe-11d3-976a-00e02913a9e0}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\webHancer Agent
DIREC|%allusersprofile%\Start menu\Programs\WinAntiVirus Pro 2006
DIREC|%programfiles%\em\
DIREC|%programfiles%\mm\
DIREC|%programfiles%\webhancer\
DIREC|%programfiles%\whInstall\
WINDO|whAgent
AUTST|webhancer agent
AUTST|webhancer survey companion
CLASS|whiehelperobi.whiehelperobj
CLASS|whiehelperobj.whiehelperobj
RKSOF|WebHancer
RKSOF|whsurvey
UINST|webhancer agent
UINST|whsurvey
FILEN|wbhshare.dll
FILEN|webhdll.dll
FILEN|whagent.exe
FILEN|whagent_update.exe
FILEN|whcc-giant.exe
FILEN|whcc_realeuser.exe
FILEN|whiehlpr.dll
FILEN|whieshm.dll
FILEN|whinstaller.exe
FILEN|whsurvey.exe
NEWPR|769|Websearch
PRCAT|5
CLSID|{1ff04b25-0a23-4a12-960c-73f8b9950436}
CLSID|{234f09fb-fe89-4c6d-9203-31832fc051c3}
CLSID|{365b9a54-e613-46e5-9db1-4f91a9de80bd}
CLSID|{37ac49e3-e906-4bd8-ae83-d0f7fb48fd17}
CLSID|{618be527-b7f5-417c-bc51-98fdc2d6de61}
CLSID|{66c22569-f05c-4a70-a142-763b337e1002}
CLSID|{69357d4e-bf4d-4651-91e9-52ecd45a0128}
CLSID|{6e21f428-5617-47f7-aed8-b2e1d8fba711}
CLSID|{6f59d850-a155-4930-98ae-689a2bc7b8e8}
CLSID|{708be496-e202-497b-bc31-9cf47e3bf8d6}
CLSID|{7b8bd940-b1ef-460c-85a2-9acaaf7f9303}
CLSIA|{87067f04-de4c-4688-bc3c-4fcf39d609e7}
CLSIA|{886dde35-e955-11d0-a707-000000521958}
CLSID|{99aa88d1-d9d3-410a-be9e-044f94c183da}
CLSID|{af8b3c81-cd19-45fb-b6be-160d27711de8}
CLSID|{bbf122a7-8a4d-45b5-9e00-0f68bc87c904}
CLSID|{c380566d-f343-42ab-987b-6b38a1a35747}
CLSID|{cabcf5e7-0c79-4f1c-909d-b9cf68fed746}
CLSID|{cae0999f-78c5-49dc-9f30-13142aaaaba4}
CLSID|{d1951679-1d52-43fc-9585-0737143585f5}
CLSID|{d8bd4ded-5bb2-4d4e-9a6a-f10244fed7d6}
CLSID|{db9a4e78-35df-4a54-b6c5-c5190ceaf949}
CLSIA|{e4463a35-7e7a-4621-8248-91307afa8ead}
CLSID|{f1616b86-9288-489d-b71a-0ccf2f1a89da}
CLSID|{f273d4ea-2025-4410-8408-251a0cd46be7}
CLSID|{fb45c451-b0e9-4407-bb6a-9361013f3e9a}
DIREC|%ALLUSERSPROFILE%\Start Menu\ProgramsWeb Search Tools\
DIREC|%programfiles%\websearch\
AUTST|ir50_32
AUTST|Mmgsvc
AUTST|Narrator
AUTST|Pfkezr
AUTST|SAK
AUTST|TBPS
AUTST|TBPSSvc
AUTST|websearch
RKSOF|toolbar
FILEN|%programfiles%\Toolbar\tbps.dat
FILEN|edowst3.exe
FILEN|zcwedowst3.exe
NEWPR|1201|WebSecurealert
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\WebSecurealert\
DIREC|%ALLUSERSPROFILE%\WebSecurealert
DIREC|%ProgramFiles%\WebSecurealert
RKSOF|Gator.com\WebSecurealert
RKSOF|WebSecurealert
UINST|WebSecurealert
FILEN|websecurealert.exe
FILEN|websecurealertsetup.exe
FILEN|websecureuninstaller.exe
FILEN|wsahelper.dll
NEWPR|2553|WebThisWebThat
PRCAT|5
DIREC|%allusersprofile%\Start Menu\Programs\wtwt\
DIREC|%ProgramFiles%\wtwt\
UINST|wtwt
NEWPR|543|Whazit
PRCAT|5
CLSID|{10955232-b671-11d7-8066-0040f6f477e4}
CLSIA|{267d5bd3-0dc2-4724-a196-7f4794fbb9eb}
CLSIA|{3b99f202-145a-4e5a-ac7b-88a36910bf5e}
CLSIA|{66f67511-2665-4c34-9e20-fac2c0954ef2}
CLSID|{c9176930-9c9f-4cba-9723-0f58c3e7ced6}
CLSIA|{ce156487-4d41-4e86-98cf-56115b9185ce}
CLSID|{d130f0d2-bcfd-4b15-a5e7-415159ef4969}
CLSID|{d5b72aed-e54a-11d6-b1b2-444553540000}
CLSIA|{d7d7004c-a763-4f8c-b0d4-55a7e017e69d}
CLSIA|{dcf0768d-ba7a-101a-b57a-0000c0c3ed5f}
CLASS|BrowserHelper.CBrowserHelper
CLASS|wharederer.Class1
RKSOF|180solutions\msbb
RKSOF|wms
UINST|redwhazit
FILEN|whattn.dll
NEWPR|2230|WhenU-BrowserToolbar
PRCAT|5
CLSID|{45e5dadb-dfdf-4fc3-a46c-dd34b6cddb38}
CLSID|{763bd795-24ae-44d7-82d8-f9a1ee799729}
CLASS|WUSE
UINST|WhenUSearchB
FILEN|%userprofile%\Local Settings\Temp\is-1PA2S.tmp
FILEN|%userprofile%\Local Settings\Temp\is-C0QLG.tmp
NEWPR|871|WhenU-ClockSync
PRCAT|5
DIREC|%programfiles%\ClockSync\
AUTST|ClockSync
UINST|ClockSync
FILEN|vvsni_sync_webinst.exe
NEWPR|18|WhenU-DesktopBar
PRCAT|5
CLSID|{20c9d850-244d-10e1-b3c1-20805e499d95}
CLSID|{711648f0-5ff5-4c81-805e-a1aedbab4951}
CLSID|{715839cd-abec-45d8-a83c-1275f2d837cd}
CLSID|{737830b7-f1f9-4bae-a8fc-1433c71bedff}
CLSID|{ba2325ed-f9eb-4830-8fce-0bc35b16969b}
CLSID|{beae14db-a12a-442d-bf77-4644e3661211}
CLSID|{c285d18d-43a2-4aef-83fb-bf280e660a97}
CLSIA|{e2f2b9d0-96b9-4b25-b90c-636ecb207d18}
CLSIA|{fc327b3f-377b-4cb7-8b61-27cd69816bc3}
CLSIA|{fee7fd53-3356-4d4d-8978-2c4ae3a7e109}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WUSE.1
DIREC|%programfiles%\VVSDL
DIREC|%programfiles%\VVSN
DIREC|%PROGRAMFILES%\WHENUSEARCH\
DIREC|%USERPROFILE%\Start Menu\Programs\WhenU
DIREC|%USERPROFILE%\Start Menu\Programs\WhenUSearch
WINDO|WhenUOffers
AUTST|SARU
AUTST|VVSN
AUTST|WhenUSearch
AUTST|WhenUSearchWHSE
CLASS|WhenU
RKSOF|WhenU
RKSOF|whenusearch
UINST|whenusearch
FILEN|%alluserprofile%\Desktop\Toolbar.lnk
FILEN|vvsn.exe
FILEN|whse_pb.min.g2inst.exe
NEWPR|2485|WhenU-FanzoneToolbar
PRCAT|5
FILEN|vvsn_fanz0110inst.exe
NEWPR|1149|WhenU-PriceBandit
PRCAT|5
AUTST|WhenUStart.exe
RKSOF|WhenUShop
UINST|whenushop
FILEN|vvsni_pbtb0100inst.exe
NEWPR|2376|WhenU-SaveNow
PRCAT|5
CLSID|{127df9b4-d75d-44a6-af78-8c3a8ceb03db}
CLSID|{43382522-a846-46f4-ac57-1f71ae6e1086}
CLSID|{572fb162-c0ba-4edf-8cff-e3846153b9b0}
CLSID|{72a836d1-bc00-43c0-a941-17960e4fb842}
CLSID|{a9aae1ab-9688-42c5-86f5-c12f6b9015ad}
CLSID|{df901432-1b9f-4f5b-9e56-301c553f9095}
REGKE|HKEY_CLASSES_ROOT\AppID\ACM.DLL
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WUSN.1
DIREC|%CommonProgramFiles%\WhenU\
DIREC|%programfiles%\savenow\
DIREC|%programfiles%\save\
DIREC|%programfiles%\VVSDL\
DIREC|%USERPROFILE%\Start Menu\Programs\WhenU\
AUTST|SaveNow
AUTST|Vicman_WhenUSave_Installer
AUTST|WhenUSave
CLASS|ACM.ACMFactory
CLASS|ACM.DLL
CLASS|WhenU.SiteSupport
CLASS|wusn
RKSOF|WhenUSave
UINST|SaveNow
UINST|WhenUSaveMsg
FILEN|saveinstcm.exe
FILEN|saveuninst.exe
FILEN|saveupdate.exe
FILEN|setupsavenow.exe
FILEN|vvsni_savenowsiteinst.exe
NEWPR|2396|WhenU-UControl
PRCAT|5
CLSID|{0a65ca2b-edb9-48b1-92da-1d92c72498e4}
CLSID|{0c4c45db-a4dc-4cf4-8f1d-8cadf97855c9}
CLSID|{28d4752f-cf84-11d1-834c-00a0249f0c28}
CLSID|{5b061650-38ae-49b4-9f5d-35396b2ceff5}
CLSID|{70271f18-b604-40fe-a8cd-15baeb11ed84}
CLSID|{8cbdba78-8cd5-4037-bd94-67cd49958d23}
CLSID|{916d4be3-6b0f-4e73-871a-17bd6ef3b2f9}
CLSID|{a001a440-e479-4fa9-8270-2cc9f0e69e2c}
CLSID|{c831c7c9-e46c-45f2-b44e-b7f72e2a9a1d}
CLSID|{cb8acef9-1085-4b47-b969-963e56aa9543}
CLSID|{f3208e7f-0e66-4f1d-bab9-ef7ec870ed24}
DIREC|%allusersprofile%\All Users\Application Data\Ucontrol\
DIREC|%CommonprogramFiles%\Ucontrol\
CLASS|UControlScanAndRemove.UControlScanner
CLASS|wss_sp_gen.Class1
CLASS|wss_sp_reg.Class1
RKSOF|Ucontrol
UINST|UControl Scan and Remove
NEWPR|2377|WhenU-WeatherCast
PRCAT|5
CLSID|{20752c25-2d97-4e6f-9ee2-94b74d202875}
CLSID|{389a5a59-1306-4389-a779-2eb9d0bc1ffb}
DIREC|%ProgramFiles%\WeatherCast\
DIREC|%USERPROFILE%\Start Menu\Programs\WeatherCast\
AUTST|WeatherCast
CLASS|WhenU.EmbedSE
RKSOF|WhenU\Weather
UINST|WeatherCast
FILEN|setupweathercast.exe
FILEN|sndbmark.dll
FILEN|weatherautocast0007.cab
FILEN|weatherautocast0018.cab
FILEN|weatherautocast0021.cab
FILEN|weatherinst.exe
FILEN|weatherinstcast0004.cab
FILEN|weatherinstcast0203.cab
FILEN|weatherinstcast1113.cab
FILEN|weatherinstibon0001.cab
FILEN|weatherinstslct0002.cab
NEWPR|2461|WhileYouSurf
PRCAT|5
UINST|While You Surf
NEWPR|2337|WhistleSoftware
PRCAT|5
CLSID|{0a88c7a6-f482-462a-8f43-f1ad8c009f50}
CLSID|{0bf6b2ca-be97-4275-8695-2
fb086be0b9b}
CLSID|{0cc38e71-6ad3-450c-8c71-50728a640b43}
CLSID|{0fbd6033-24c5-45d2-a1e5-38c46ed3b135}
CLSID|{220e39c3-b081-4719-ab1a-9a884dcbd05c}
CLSID|{27557cf1-a237-496d-8c8f-08f3844c6a8b}
CLSID|{322400d5-8fb0-45ba-8f09-0e837d57493b}
CLSID|{3fecb959-1fdd-4803-850a-ca3f2859f5ab}
CLSID|{54a770f4-d5f3-42ae-9fd5-390a6a4d85e7}
CLSID|{568f3ba7-b0e2-4a83-b8b6-319631c4622c}
CLSID|{7ea005fe-90da-4bc7-955b-9face4a2069c}
CLSID|{80e6ee09-3db1-4627-a7c9-dad7cfbdf05f}
CLSID|{8179b6d6-513d-45dc-b910-aa329a524142}
CLSID|{889395bf-f7f7-4023-b42e-6074de380ea5}
CLSID|{8d9bffc9-e027-4ea3-8ae9-8dbefed2fb93}
CLSID|{8da46338-ba81-4065-b7b9-36450e42b017}
CLSID|{92a17f40-e69b-44fa-9b8a-aaf7dbe413af}
CLSID|{930cb039-564e-4c04-b6a8-8b31bfb28347}
CLSID|{93cf2521-df05-41f4-b803-5eb17c4bb424}
CLSID|{99258154-5666-4561-ad45-c76ae7077b70}
CLSID|{9f05772f-c5ab-4491-b8e1-a5a1a0b883a7}
CLSID|{a16e4ecf-12aa-49e2-9891-ece57af678b9}
CLSID|{a58aacf2-6e0f-4465-8c81-52151e60e07b}
CLSID|{a625720f-c6eb-4806-b3d6-8fc4df89db94}
CLSID|{aa5955f9-b090-4d3b-ad7f-c9b46509bb87}
CLSID|{ac8b00eb-0b68-49a6-a278-cbba09e8151e}
CLSID|{b135ed26-a131-4861-b081-35c69398a704}
CLSID|{b8848f69-e8e2-4952-90f2-bc4ef0c22243}
CLSID|{bb46ac71-9f97-4518-b0d0-f3008b65cf88}
CLSID|{c7a2084b-969c-439a-96e8-176bf9a93879}
CLSID|{d02fac77-c2e0-44d9-aa62-e9f40831ca8e}
CLSID|{d1bcd273-d241-4bff-a2a0-e45b3b4eb27b}
CLSID|{d5e6a641-453e-4650-a49a-fa912a870827}
CLSID|{ebcf7b0e-2277-4ee4-95ee-3d542cdb8191}
CLSID|{f75448f7-4f62-45fa-9bc1-4250bb4d87c9}
CLSID|{fdc2fa83-0e09-427a-a4e6-04fb98667c32}
CLSID|{fe2c03f1-eb17-4017-9c22-99c65870b9ec}
DIREC|%ProgramFiles%\WhistleSoftware\
CLASS|IMCUpdate.Update
CLASS|ImcWselParser.WselParser
CLASS|WhistleHlprObj.WhistleHlprObj
CLASS|WselServices.WselLogServices
CLASS|WselServices.WselNetworkServices
CLASS|WselServices.WselXmlServices
CLASS|WselTypeLibrary.User
CLASS|WselTypeLibrary.WselService
CLASS|WselTypeLibrary.WselServiceCol
RKSOF|WhistleSoftware
UINST|Whistle Software
NEWPR|2058|WierdontheWeb
PRCAT|5
DIREC|%programfiles%\WeirdOnTheWeb\
AUTST|WeirdOnTheWeb
RKSOF|WeirdOnTheWeb
UINST|WeirdOnTheWeb
FILEN|%userprofile%\favorites\weirdontheweb.url
FILEN|weirdontheweb_topc.exe
NEWPR|2216|Win32.Stervis.b
PRCAT|5
SERVK|SvcProc
NEWPR|2522|Wina
PRCAT|5
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WinA
DIREC|%ProgramFiles%\WinA\
UINST|WinA
NEWPR|796|WinAd
PRCAT|5
CLSID|{002eb272-2590-4693-b166-fbd5d9b6fea6}
CLSID|{53d3c442-8fee-4784-9a21-6297d39613f0}
DIREC|%ProgramFiles%\Winad Client
AUTST|Winad Client
AUTST|WNAD
NEWPR|2764|Winadiscount Toolbar
PRCAT|5
CLSID|{4961a993-7f48-4c50-a30e-d597ac571707}
CLSID|{4e7bd74f-2b8d-469e-87be-a334b786b339}
DIREC|%ProgramFiles%\winadiscount\
CLASS|winadiscount.WINADISCOUNT
CLASS|winadiscount.WINADISCOUNTMenu Button
CLASS|winadiscount.WINADISCOUNTToggle Button
RKSOF|winadiscount
UINST|winadiscount
NEWPR|2688|Windows AdService
PRCAT|5
DIREC|%ProgramFiles%\Windows AdService\
AUTST|Windows AdService
RKSOF|Windows AdService
UINST|Windows AdService
NEWPR|3298|Windows FastS Toolkit
PRCAT|5
CLSID|{e3231ba4-4271-402e-b20c-d5cfff70f9d4}
AUTST|fasts_on
RKSOF|fasts
UINST|fasts
NEWPR|775|Windows Search Bar
PRCAT|5
CLSID|{9fb534e3-67cb-4307-ae0a-9e8b5581be2c}
CLSID|{a1dd937d-71e1-4bb5-bd5d-1b01b9cb1c2f}
NEWPR|1148|Windupdates
PRCAT|5
CLSIA|{15ad4789-cdb4-47e1-a9da-992ee8e6bad6}
CLSIA|{15ad6789-cdb4-47e1-a9da-992ee8e6bad6}
CLSID|{962f12ae-2773-4beb-99ea-b5c3ab9a6606}
DIREC|%programfiles%\Admilli Service
DIREC|%programfiles%\AdTools Service
DIREC|%ProgramFiles%\DeskAd Service
DIREC|%programfiles%\winad client\
DIREC|%programfiles%\windows adcontrol
DIREC|%ProgramFiles%\Windows AdTools
DIREC|%ProgramFiles%\Windows ControlAd
DIREC|%ProgramFiles%\Windows ServeAd
DIREC|%programfiles%\windows taskad
DIREC|%programfiles%\windupdates\
AUTST|Admilli Service
AUTST|AdTools Service
AUTST|DeskAd Service
AUTST|Media Access
AUTST|msccrt
AUTST|qfyqakn.dll
AUTST|system spool
AUTST|Windows AdTools
AUTST|Windows ControlAd
AUTST|Windows ServeAd
AUTST|Windows TaskAd
AUTST|WindUpdates
AUTST|winform
AUTST|winupdate
AUTST|winupdtl
CLASS|AdManCtlx.Installer
CLASS|BridgeX.Installer
CLASS|MediaAccX.Installer
CLASS|WinadX.Installer
CLASS|WinStatX.Installer
RKSOF|Admilli Service
RKSOF|AdStatus Service
RKSOF|AdTools Service
RKSOF|DeskAd Service
RKSOF|Preview AdService
RKSOF|t5c
RKSOF|t5d
RKSOF|t5e
RKSOF|t5f
RKSOF|t5r
RKSOF|Windows TaskAd
RKSOF|WindUpdates
RKSOF|WinUpdt
UINST|Admilli Service
UINST|AdTools Service
UINST|DeskAd Service
UINST|Wind Updates
UINST|Windows TaskAd
FILEN|%windir%\system32\netut80ex.vxd
FILEN|%windir%\system32\winup2date.dll
FILEN|%windir%\system32\winupdt.008
FILEN|%windir%\system32\winupdt.bin
FILEN|bridge-c18.cab
FILEN|mediaaccess.exe
FILEN|mediaacck.exe
FILEN|winad.exe
FILEN|winctladshift.dll
FILEN|winka.exe
NEWPR|942|WinFavorites
PRCAT|5
CLSID|{4fdbdbad-fefe-4c4c-9cc1-1181052afb12}
CLSID|{80bb7465-a638-43b5-9827-8e8fe38dfcc1}
CLSID|{b88a3af1-4f1b-4400-8ffb-3fcb108ce115}
CLSID|{c094876d-1b0e-46fa-b6a6-7ffc0f970c27}
CLSID|{ddaf2479-6f00-4599-998a-3ed75686c6d0}
DIREC|%programfiles%\winfavorites
AUTST|oljxtggp
AUTST|WinFavorites
CLASS|bridge.brdg
RKSOF|winfavorites
UINST|win favorites
NEWPR|1712|WinFetcher
PRCAT|5
AUTST|imr1x
NEWPR|1443|Winpage
PRCAT|5
CLSID|{12df6e3e-6272-4ae8-880b-2158d60791c0}
CLSID|{c4c16842-a83e-4fc1-b9ef-995f764da9b2}
CLSID|{f31ef3c5-dabf-4258-9cb8-b11b52c94d8c}
DIREC|%ProgramFiles%\Homepage
CLASS|WinPageBHO.DLL
CLASS|WinPageBHO.WinPageIEExtension
NEWPR|624|Winpup
PRCAT|5
CLSIA|{9387b9e0-3da2-436e-88e5-fa09ae3a48c0}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\pup
AUTST|asauthr
AUTST|dhcpv
AUTST|dwwizh
AUTST|qlsrv32s
AUTST|svidc32m
AUTST|win32app
CLASS|pup.setup
RKSOF|pup
NEWPR|609|Winshow
PRCAT|5
CLSIA|{6cc1c918-ae8b-4373-a5b4-28ba1851e39a}
DIREC|%APPDATA%\winshow\
CLASS|WinShow.ViewSource
RKSOF|WinShow
FILEN|msupdater.exe
FILEN|winshow.dll
NEWPR|1136|Winspoe
PRCAT|5
CLSID|{043b5d00-92a9-4cae-a3d8-a4b4b8d52bb1}
NEWPR|2352|Winsync
PRCAT|5
CLSID|{6ec11407-5b2e-4e25-8bdf-77445b52ab37}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\woualo
UINST|WebNexus
FILEN|mynexus.exe
FILEN|webnexus.exe
NEWPR|1784|WishBone
PRCAT|5
CLSID|{08e62c6d-babd-4be9-a015-ecfe9cc76997}
CLSID|{10cd7efc-7d1a-4599-ab49-9249c714b87c}
CLSIA|{3aa90bc2-58c0-4f4d-a87c-2c6f3d3cd5fe}
CLSID|{40930a0f-68cc-4b81-848a-77a78f85fa7b}
CLSID|{4fd85670-606a-42e9-bba5-2bc63493b677}
CLSID|{86f4ad51-ee90-409d-944b-fdb0c939b41c}
CLSID|{87b1e57c-ff70-4c69-9ce8-57cb8f67aba8}
CLSID|{aeef5ccc-71c7-4053-88a4-6cb87fd4e461}
CLSID|{b004262d-5762-4daa-a222-3b9a738c83ea}
CLSID|{b0931261-03c3-4bb3-9ce1-22bfda3af445}
CLSID|{b6ce642a-2171-4661-bb46-aed01c2ed9ec}
CLSID|{c331bd6e-06ab-41a0-b95f-d7ca379aceaa}
CLSID|{cc4a4cd1-e441-4a03-941c-e183bce357e7}
CLSID|{da3db988-d1fb-4919-a684-78e6a5358340}
CLSID|{db2e7bc7-104f-42b5-aae3-921e3057db06}
CLSID|{eaa87376-c391-494e-9da2-2bd9c798e54f}
DIREC|%WINdir%\system32\WBM\
CLASS|Gigel.ScriptCallback
CLASS|Keys.KeyWords
CLASS|MenuContainer.MenuHolder
CLASS|MenuContainer.RegAcess
CLASS|MenuContainer.WebSink
CLASS|MicroInstaller.WBMInstaller
CLASS|WBM.AtlBrCon
CLASS|WBM.ExplorerBar
CLASS|WBM.WebMonitor
CLASS|Wbmbar.ViewSource
CLASS|Wbmbar.WBMToolBar
RKSOF|WBInstaller
RKSOF|WBM
RKSOF|Wishbone Media
UINST|WBInstaller
NEWPR|29|WNAD
PRCAT|5
FILEN|wnad-update.exe
FILEN|wnad.exe
NEWPR|1713|Wotch
PRCAT|5
AUTST|media_manager
AUTST|media_stub
NEWPR|483|WurldMedia
PRCAT|5
CLSID|{01fb9c55-fc66-4476-a199-389241193188}
CLSIA|{1b80440d-b4c0-49d7-8d2f-77f16777629b}
CLSIA|{2737a6c0-7e24-11d7-b299-00e0297e0844}
CLSIA|{3a279869-c6b6-4410-a041-0435de6ad916}
CLSIA|{40ac4d2d-491d-11d4-aaf2-0008c75dcd2b}
CLSID|{48f35889-7f47-4a93-8876-7ab20324e5d7}
CLSID|{525bbd23-1863-46c6-86d6-5f9a3715d44e}
CLSIA|{5a3a5040-4210-11d7-bd2e-00080e34122f}
CLSIA|{6270dfc1-edfb-4bc4-be8c-842740ba290b}
CLSIA|{8a880893-e6b2-4c29-b168-181a4ef6b852}
CLSID|{8e9c4f32-bd3f-4c49-9af5-3f4c5d32ebd7}
CLSIA|{98d7b53e-b1d2-4755-b0a4-703e18ff91e8}
CLSID|{a83e42b1-1ae7-4ce6-b128-ab0f4a126b2c}
CLSIA|{bfbae8da-9920-4166-a5a4-ebd03f59abf5}
CLSIA|{cdbcfeae-10ba-482c-9f6e-fc67207082d8}
CLSIA|{d14641fa-445b-448e-9994-209f7af15641}
CLSIA|{f325e940-45ee-11d7-a420-444553540000}
CLASS|Mobho.IEHlprObj
CLASS|Tchk.TChkBHO
RKSOF|morp
RKSOF|rdxr
FILEN|bpboh.dll
FILEN|m030106shop.dll
NEWPR|2933|X Password Manager
PRCAT|5
DIREC|%ProgramFiles%\X Password Manager\
DIREC|%userprofile%\Start Menu\Programs\X Password Manager\
UINST|X Password Manager
FILEN|%userprofile%\Desktop\X Password Manager.lnk
NEWPR|2702|Xagon - Atomic Mp3 Finder
PRCAT|5
DIREC|%ProgramFiles%\Xagon\
RKSOF|Xagon
UINST|Atomic Mp3 Finder
NEWPR|2587|Xbarre
PRCAT|5
CLSID|{4e7bd74f-2b8d-469e-d7ec-ed6db68dfa7d}
CLSID|{4e7bd74f-2b8d-469e-d7ec-ed6db68dfa7e}
CLSID|{4e7bd74f-2b8d-469e-d7ec-ed6db68dfa7f}
DIREC|%ProgramFiles%\xbarre\
CLASS|xbarre.XBARRE
CLASS|xbarre.XBARREMenu Button
CLASS|xbarre.XBARREToggle Button
RKSOF|XBARRE
UINST|XBARRE
NEWPR|1828|Xhrmy
PRCAT|5
AUTST|xhrmy
RKSOF|Xhrmy
NEWPR|1220|Xlocator/Winlocator
PRCAT|5
CLSIA|{121ac498-3f3a-4c39-9bea-cfc4ea809fdf}
CLSID|{89aeab46-8e8a-4045-9003-5614bfbfe90b}
CLSID|{8f0d6eed-bc11-4e7f-8276-9748947e4a50}
AUTST|winlocatorupdate
CLASS|WinLocator.Portal
CLASS|WinLocatorHelper.bho
CLASS|XlocatorInstall.Install
RKSOF|winlocator
FILEN|%WINdir%/winlocator.reg
NEWPR|1234|Xrenoder
PRCAT|5
UINST|AutoUpdate
NEWPR|430|Xupiter
PRCAT|5
CLSID|{07fa131e-2eb2-446f-93d2-9f877320010b}
CLSID|{1348e05a-21c7-4134-b4a4-3c12234fca3f}
CLSID|{1a8b567b-bd3f-44a1-8b94-f50d37a1914e}
CLSID|{2662bdd7-05d6-408f-b241-ff98face6054}
CLSIA|{280168bc-76bf-4cd0-b835-3d686efa8ddc}
CLSID|{29089b98-af05-4769-b627-86a745d4b672}
CLSID|{3a021d2f-5f75-47f5-9bab-a137e1fb015f}
CLSIA|{3c5ba506-6c30-4738-9ced-797acadea8dc}
CLSID|{3f4386e5-2fbe-44a8-81cf-4b792490605f}
CLSID|{43732063-1bda-45a0-bbee-13e014cb4041}
CLSID|{43f1b4ad-92ef-4db3-bda9-12335b012dd0}
CLSID|{4a0f42b7-a61b-4131-bf41-bf05a2635bfd}
CLSID|{55b201ff-c057-e521-6d17-0489b6cf9930}
CLSIA|{57e69d5a-6539-4d7d-9637-775de8a385b4}
CLSID|{6e6dd93e-1fc3-4f43-8afb-1b7b90c9d3eb}
CLSIA|{702ad576-fddb-4d0f-9811-a43252064684}
CLSID|{74232635-a013-49f2-b869-1b1ab932d944}
CLSID|{7f0f5d9a-84cb-11d4-8137-00500487b1c5}
CLSID|{7f0f5da6-84cb-11d4-8137-00500487b1c5}
CLSID|{83b027c5-1489-4ec5-a290-47da8058ac04}
CLSID|{899be974-d575-48bb-a9c7-1d24e8042be4}
CLSID|{8bee173b-c006-4f0e-acd2-84a882bebcff}
CLSID|{909e0059-f545-42de-9d2c-cc4a3e336ec3}
CLSID|{910e67a6-bd53-46df-8434-41498b7d22f7}
CLSID|{9464c98e-b5f1-4c6a-bd3f-9696e3bd081e}
CLSID|{9dbdd71c-0a7f-48ac-9ffa-e102b3750b9d}
CLSIA|{a27cfcae-9351-4d74-bffc-21eb19693d8c}
CLSID|{b0db6360-8d7f-11d4-8137-00500487b1c5}
CLSID|{bf986691-7f7b-4f94-85e0-20e75350701f}
CLSID|{bfa2c963-fc24-4770-8c19-0d5a1cd58df9}
CLSID|{c09fb84d-b9ed-43eb-afed-f145c26cb839}
CLSID|{c0cad17e-00a3-4f40-9015-d569c3114ba3}
CLSID|{c2e56e18-2f04-4ab9-9333-b2db3c350956}
CLSID|{c6c2871f-7467-4a35-90fa-9e9894bc1916}
CLSID|{c81b4b57-b06b-409d-aed0-028051683796}
CLSID|{ce2eab19-e31d-43ca-a860-f95a2ca50040}
CLSIA|{d48f2e28-68e2-4920-9848-d6e6c7ab3eb7}
CLSID|{d686db39-659a-491a-a35c-60b99495c16e}
CLSIA|{d7b3e460-9968-4191-bd6f-beed1bc18482}
CLSID|{e9cbbeed-20b6-456c-8589-cf364d9d2370}
CLSID|{eb07a6d3-8e36-11d4-8138-00500487b1c5}
CLSID|{f8c5ea77-7d72-405c-b90a-093655b0f544}
CLSID|{ffe56921-248b-4c75-9eee-01706310e371}
DIREC|%programfiles%\Sqwire\
DIREC|%programfiles%\Xupiter\
AUTST|buwhtje.dll
AUTST|xupitercfgloader
AUTST|XupiterStartup
CLASS|xtsearch.xtsearchhook
CLASS|xtupdate.xt
CLASS|xupitertoolbar.band
RKSOF|Xupiter
UINST|Xupiter
FILEN|bobsaver.exe
FILEN|bobsaver.scr
FILEN|oeloader.dll
FILEN|popunder.exe
FILEN|tsl_rc0.dll
FILEN|xtcfgloader.exe
FILEN|xtcfgrunner.exe
FILEN|xtsearch.dll
FILEN|xtupdate.dll
FILEN|xupiterstartup.exe
FILEN|xupiterstartup2003.exe
FILEN|xupitertoolbar.dll
FILEN|xupitertoolbarinstaller.exe
FILEN|xupitertoolbarloader.cab
FILEN|xupitertoolbarloader.exe
FILEN|xupiterwauninstaller.exe
NEWPR|2426|Xware
PRCAT|5
CLSIA|{42b1c70d-9823-41f7-810a-682da294d868}
AUTST|sload
AUTST|xware
IEZON|xxsware.com
NEWPR|610|xxxtoolbar
PRCAT|5
CLSIA|{386a771c-e96a-421f-8ba7-32f1b706892f}
CLSIA|{4418dd4d-7265-4c32-bc0a-3fdb3c2da938}
CLSIA|{ef86873f-04c2-4a95-a373-5703c08efc7b}
IEZON|*.offshoreclicks.com
IEZON|.teensguru.com
IEZON|xxxtoolbar.com
FILEN|best.exe
NEWPR|2848|Yapbrowser
PRCAT|5
DIREC|%allusersprofile%\Start Menu\Programs\YapBrowser
DIREC|%programfiles%\yapbrowser
UINST|yapbrowser
FILEN|%allusersprofile%\Desktop\YapBrowser.lnk
FILEN|%allusersprofile%\Start Menu\Programs\Startup\YapBrowser.lnk
NEWPR|3056|Yazzle Cowabanga
PRCAT|5
DIREC|%ProgramFiles%\Cowabanga\
RKSOF|Cowabanga
UINST|Cowabanga
UINST|Yazzle1264Oin
FILEN|%USERPROFILE%\Start Menu\Programs\Games\Cowabanga.lnk
FILEN|yazzle1119oinuninstaller.exe
FILEN|yazzle1264oinadmin.exe
FILEN|yazzle1264oinuninstaller.exe
FILEN|yazzlebundle-1264.exe
NEWPR|2897|Yazzle Snow Ball War
PRCAT|5
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Yazzle Snowball Wars
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yazzle Snowball Wars
DIREC|%programfiles%\snowball wars
DIREC|%ProgramFiles%\Yazzle Snowball Wars\
DIREC|%userprofile%\Start Menu\Programs\Yazzle Snowball Wars\
AUTST|Snowball Wars
RKSOF|Yazzle Snowball Wars
UINST|Snowball Wars
UINST|Yazzle Snowball Wars
NEWPR|2355|Yazzle Sudoku
PRCAT|5
CLSID|{665ac8e7-8b9b-40d9-a24d-c134052b6168}
CLSID|{8b7cd17e-428b-4ee7-bbcd-21875fa05d7f}
CLSID|{907977fb-8835-483f-9979-ae3101dd3d17}
CLSID|{95b10d86-f27f-40b6-9a57-53db278546d0}
CLSID|{95c2547b-0785-4278-9aea-ce65d78d853d}
REGKE|HKEY_CLASSES_ROOT\YazzleSudokuGame
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Yazzle Sudoku
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\YazzleSudokuGame
DIREC|%ProgramFiles%\Yazzle Sudoku\
DIREC|%userprofile%\Start Menu\Programs\Yazzle Sudoku\
AUTST|FT_SilentSudokuInstaller.exe
AUTST|ms05447449-1862
AUTST|sys02862447449-1
CLASS|.sdu
CLASS|YazzleSudokuGame
RKSOF|Tanw
RKSOF|Yazzle Sudoku
UINST|Y1123Oin
UINST|Y1304Oin
UINST|Yazzle1162Oin
UINST|Yazzle1438Oin
UINST|Yazzle1452Oin
UINST|YazzleSudoku
FILEN|ageu_silentsudokuinstaller.exe
FILEN|ageu_sudokuinstaller.exe
FILEN|ft_silentsudokuinstaller.exe
FILEN|gs_silentsudokuinstaller.exe
FILEN|yazzle1119oinadmin.exe
FILEN|yazzlebundle-1119.exe
FILEN|yazzlebundle-1304.exe
FILEN|yazzlebundle-1438.exe
FILEN|yazzlebundle-1452.exe
NEWPR|1285|YellowPages
PRCAT|5
CLSID|{47fe5d70-9aa2-40f1-9c6b-12a255f085ea}
CLSID|{49f2248d-1734-4b0f-a7b8-542e526ee07c}
CLSID|{679695bc-a811-4a9d-8cdf-ba8c795f261a}
CLSID|{d797ad6c-6447-4db4-91d0-090344408e72}
CLASS|YellowPages.YellowBar
NEWPR|2395|Youcouldwinthis
PRCAT|5
CLSID|{d7950ab4-67f5-458e-a37d-9f2de7f250ac}
DIREC|%ProgramFiles%\YOUCOULDWINTHIS\
CLASS|AdCom.AdCom
UINST|{534902F9-3758-4304-BFC0-24800B4E5FB9}
NEWPR|3063|Your Screen
PRCAT|5
DIREC|%programfiles%\freeze.com
DIREC|%programfiles%\yourscreen
CLASS|Freeze.DesktopManager.BrowserHelper.DLL
CLASS|FreezeDesktopManagerBrowserHel.Browse
CLASS|FreezeDesktopManagerBrowserHel.BrowserH
RKSOF|Freeze
UINST|Living Waterfalls Wallpaper #1
UINST|YourScreen
FILEN|waterfalls1awfree.exe
FILEN|yourscreen_4_pch.exe
NEWPR|974|YourSiteBar
PRCAT|5
CLSID|{03b800f9-2536-4441-8cda-2a3e6d15b4f8}
CLSIA|{42f2c9ba-614f-47c0-b3e3-ecfd34eed658}
CLSID|{4ee12b71-aa5e-45ec-8666-2db3ad3fdf44}
CLSIA|{771a1334-6b08-4a6b-aedc-cf994ba2cebe}
CLSID|{bf06da8e-2beb-4816-9bbd-f7625246e245}
CLSID|{db447818-96b4-40df-8a55-720da496f514}
CLSID|{dfbcc1eb-b149-487e-80c1-cc1562021542}
DIREC|%programfiles%\YourSiteBar
DIREC|%programfiles%\YourSitetoolbar
CLASS|Ysb.YsbObj
CLASS|YSBactivex.Installer
RKSOF|YourSiteBar
UINST|YourSiteBar
FILEN|yoursitebar.exe
NEWPR|795|Zamingo
PRCAT|5
AUTST|Adstartup
FILEN|adstartup.exe
FILEN|ieenhancer.dll
NEWPR|1987|Zango
PRCAT|5
CLSIA|{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8}
CLSIA|{99410cde-6f16-42ce-9d49-3807f78f0287}
CLSID|{d28cd14c-50be-4cfa-951e-b37f25da3472}
CLSIA|{deceaaa2-370a-49bb-9362-68c3a58ddc62}
CLSID|{ea0d26bd-9029-431a-86e0-83152d67828a}
DIREC|%allusersprofile%\Start Menu\Programs\Zango Games\
DIREC|%programfiles%\Zango Games\
DIREC|%programfiles%\ZangoClient\
DIREC|%programfiles%\zango\
DIREC|%userprofile%\Start Menu\Programs\Zango Games\
DIREC|%userprofile%\Start Menu\Programs\Zango\
CLASS|ncmyb.SABHO
CLASS|saix.installercaller
RKSOF|zanu
UINST|zanu
FILEN|%programfiles%\zango\zango.exe
FILEN|zango.exe
FILEN|zangoinstaller.dll
FILEN|zangoinstaller.exe
FILEN|zangolib.dll
FILEN|zangomuncher.exe
FILEN|zanuhook.dll
NEWPR|2373|Zango Grab&Burn
PRCAT|5
DIREC|%programfiles%\Zango Applications\
DIREC|%userprofile%\Start Menu\Programs\Zango Applications\
RKSOF|www.zango
UINST|Zango Grab & Burn
UINST|Zango Grab & Burn DisplayIcon
FILEN|%userprofile%\desktop\Zango Grab & Burn.lnk
NEWPR|2176|Zango Messenger
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\Zango
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\Zango Applications
DIREC|%programfiles%\Zango Applications
AUTST|zanu
RKSOF|Zango Messenger
UINST|Zango Messenger
NEWPR|2568|Zango Times
PRCAT|5
DIREC|%appdata%\Zango TvTimes\
UINST|Zango TV Times
NEWPR|2298|Zango Toolbar
PRCAT|5
CLSID|{01bf19c2-59d3-43e9-a2cc-c2d62d8878d3}
CLSID|{f1f040d5-e8f8-4680-b101-9334e9773841}
REGKE|HKEY_CLASSES_ROOT\AppID\ZangoToolbar.DLL
DIREC|%allusersprofile%\Start Menu\Programs\Zango\
DIREC|%programfiles%\Zango Programs\
DIREC|%ProgramFiles%\Zango Toolbar\
AUTST|zango
CLASS|ZangoToolbar.DLL
CLASS|ZangoToolbar.ZCToolBand
RKSOF|zango
RKSOF|Zango Programs
UINST|zango
UINST|Zango Toolbar
FILEN|zangohook.dll
FILEN|zangotb.dll
FILEN|zangotbuninstaller.exe
NEWPR|2902|Zango TV
PRCAT|5
CLSID|{5490ef03-553e-42d6-a437-9bfb70c45231}
DIREC|%allusersprofile%\Start Menu\Programs\Zango Programs\
DIREC|%allusersprofile%\Start Menu\Programs\Zango Programs\Zango TV\
DIREC|%ProgramFiles%\Zango Programs\Zango TV\
DIREC|%systemdrive%\WINNT\Installer\{5490EF03-553E-42D6-A437-9BFB70C45231}\
FILEN|%
allusersprofile%\Desktop\Zango TV.lnk
NEWPR|2573|Zango-AirHockey
PRCAT|5
DIREC|%allusersprofile%\Local Settings\Temp\Zango\AirHockey\
DIREC|%allusersprofile%\Start Menu\Programs\Zango Games\Air Hockey\
DIREC|%ProgramFiles%\Zango Games\AirHockey\
RKSOF|MLP\AirHockey
UINST|Air Hockey
NEWPR|2567|Zango-Astrology
PRCAT|5
DIREC|%appdata%\Zango Astrology\
UINST|Zango Astrology
NEWPR|2556|Zango-Checkers
PRCAT|5
NEWPR|2532|Zango-Chess
PRCAT|5
DIREC|%allusersprofile%\Start Menu\Programs\Zango Games\Chess\
DIREC|%ProgramFiles%\Zango Games\Chess\
UINST|Chess
NEWPR|2540|Zango-DavidvsGoliath
PRCAT|5
NEWPR|2577|Zango-Foosball
PRCAT|5
DIREC|%allusersprofile%\Local Settings\Temp\Zango\
DIREC|%allusersprofile%\Start Menu\Programs\Zango Games\Foosball\
DIREC|%ProgramFiles%\Zango Games\Foosball\
RKSOF|Lantern Games\GameRoom\Foosball
UINST|Foosball
NEWPR|2338|Zango-JadeShadow
PRCAT|5
FILEN|jadeshadowinstall.exe
FILEN|jadeshadowsetup.exe
NEWPR|2559|Zango-Libraryoftheages
PRCAT|5
UINST|Library of the Ages
NEWPR|2566|Zango-MovieTimes
PRCAT|5
CLSID|{56f1d444-11bf-4879-a12b-79cf0177f038}
DIREC|%appdata%\Zango MovieTimes\
CLASS|ClientAX.ZangoClientAX
CLASS|zangohook.SABHO
UINST|Zango Movie Times
NEWPR|2570|Zango-Muncher
PRCAT|5
UINST|Zango Muncher
NEWPR|2563|Zango-SecretChamber
PRCAT|5
UINST|Secret Chamber
NEWPR|2558|Zango-Shuffleboard
PRCAT|5
UINST|Shuffle Board
NEWPR|2543|Zango-Solitaire
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\Zango Games\Zango Solitaire\
DIREC|%ProgramFiles%\Zango Games\Zango Solitaire\
UINST|Zango Solitaire
NEWPR|2598|Zango-WallsofJericho
PRCAT|5
UINST|Walls of Jericho
NEWPR|2497|Zango-Windwords
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\Zango Games\Wind Words\
DIREC|%ProgramFiles%\Zango Games\Wind Words\
UINST|Wind Words
NEWPR|1714|ZapSpot
PRCAT|5
DIREC|%APPDATA%\Application Data\ZapSpot\
DIREC|%USERPROFILE%\My Documents\My ZapSpot\
CLASS|ZapSpot.ZML
FILEN|zapspot.exe
NEWPR|2791|Zeno Search Assistant
PRCAT|5
AUTST|BrowserUpdateSched
AUTST|ExploreUpdSched
AUTST|{2F-F8-82-28-ZN}
AUTST|{E4-44-4B-B0-ZN}
UINST|Enhanced Ads by Zeno
UINST|Zeno Search Assistant
FILEN|%userprofile%\Start Menu\Programs\Startup\Zeno.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Startup\Z_Start.lnk
FILEN|%windir%\system32\msnav32.ax
FILEN|dwdsregt.exe
FILEN|nt68rrtc12.sys
FILEN|zicorn001.exe
NEWPR|2359|ZeroPopUp Toolbar
PRCAT|5
DIREC|%programfiles%\ZeroPopupBar\
CLASS|ToolBand.ToolBandObj
UINST|ZeroPopUpBar
NEWPR|957|ZestyFind
PRCAT|5
CLSID|{5cf8a355-f8c6-4883-9c25-49d01a7d25be}
CLSID|{86227d9c-0efe-4f8a-aa55-30386a3f5686}
CLSIA|{a16e6189-a1dd-4696-9806-0324c145d794}
CLSIA|{ca034dcc-a580-4333-b52f-15f98c42e04c}
CLSIA|{fe4bbea8-1efd-4b8a-bd1b-341ccdbeeaa6}
DIREC|%ProgramFiles%\YourSiteBar\
AUTST|Findwavemeetloud
AUTST|gdaj
AUTST|kvern16.dll
AUTST|Trans Comp
AUTST|vernn16.dll
FILEN|%USERPROFILE%\desktop\Cheap Holiday Travel.url
FILEN|%USERPROFILE%\desktop\Free Online Music.url
FILEN|icont.exe
NEWPR|2001|Zeta
PRCAT|5
REGKE|HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZESOFT
REGKE|HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ZESOFT
DIREC|%windir%\system32\jcngn
DIREC|%windir%\system32\omjffbrq
DIREC|%windir%\system32\qkoj
DIREC|%windir%\system32\yjtgnqsu
AUTST|Gmedia2
AUTST|nfxpbvd
AUTST|spiven
FILEN|%windir%\system32\spiven.exe
SERVI|nfxpbvdjcngn
SERVI|Zesoft
NEWPR|3443|Zhong
PRCAT|5
CLSID|{0cb66ba8-5e1f-4963-93d1-e1d6b78fe9a2}
CLSID|{2a0176fe-008b-4706-90f5-bba532a49731}
CLSID|{3ce496d1-1746-41cd-9489-3c0b93df10e2}
CLSID|{42d25f15-cf07-4a72-b191-db0792bf310c}
CLSID|{967a494a-6aec-4555-9caf-fa6eb00acf91}
CLSID|{9692be2f-eb8f-49d9-a11c-c24c1ef734d5}
CLSID|{a8954909-1f0f-41a5-a7fa-3b376d69e226}
CLSID|{d0903a3b-f0ea-434a-9742-98c5335c7946}
NEWPR|692|ZipClix
PRCAT|5
CLSIA|{319a68db-06d0-46da-9f93-a810d5a70836}
CLSID|{bbcd25c8-a31e-4dfb-b204-b54bba477b23}
CLSID|{ec34a4b3-809a-4a71-88d4-55b5183d6041}
DIREC|%programfiles%\zipclix\
CLASS|zipclix
CLASS|zipclixobj.zipclixobj
RKSOF|zipclix
UINST|zipclix
FILEN|zipclix.dll
FILEN|zipclix.exe
NEWPR|921|Zippylookup
PRCAT|5
CLSID|{19e41a2d-bd9d-48bb-9576-27b2cf0877c0}
CLSID|{49256fe8-6394-4ace-939c-22f35ca042ad}
NEWPR|2857|Zone-DL.Plugin
PRCAT|5
CLSIA|{2473bf2d-ca0a-11da-88db-0050bf2938e1}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , dns-look-up.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , netbios-wait.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , netsearchsoft.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.dns-look-up.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.netbios-wait.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.netsearchsoft.com
DIREC|%programfiles%\Download Plugin\
WINDO|windWWAA
WINDO|wwBYAwnd
AUTST|close jump
CLASS|DownloadPlugin.DLPlugin
UINST|Download Plugin (ActiveX)
UINST|Wait long soft
FILEN|axdlplug-1.5.0.0-0281-setup.exe
FILEN|axdlplug-1.5.0.0-147-setup.exe
FILEN|npdlplug-1.5.0.0-147-setup.exe
NEWPR|1757|Zoombar
PRCAT|5
NEWPR|1342|Zserv
PRCAT|5
CLSID|{00000000-c1ec-0345-6ec2-4d0300000000}
NEWPR|2276|ZToolbar
PRCAT|5
CLSID|{a55c3ba7-db1e-4652-867e-055ceafe8018}
CLSID|{ef77d50b-5767-4e0e-a3a4-098670025f1d}
CLSID|{fff5092f-7172-4018-827b-fa5868fb0478}
CLASS|Ztoolbar
CLASS|ZToolbar.activator
CLASS|ZToolbar.ParamWr
CLASS|ZToolbar.StockBar
RKSOF|ZsearchCo
FILEN|%windir%\blank.mht
FILEN|%windir%\system32\ztoolbar.bmp
FILEN|%windir%\system32\ztoolbar.xml
NEWPR|1119|Zuvio
PRCAT|5
CLSID|{30a56549-9d5b-4d34-afa7-440a7f0538a9}
CLSIA|{419cc403-e9fc-4c90-bbe6-c8ea9159e49d}
CLSIA|{ed2e4bb5-60ea-4624-9de2-998e441c699b}
DIREC|%ProgramFiles%\Open Site
AUTST|Open Site
CLASS|OpenSite.opensite_install
UINST|Open Site
FILEN|%systemdrive%\msole32.exe
FILEN|opensite.cab
FILEN|opensite.exe
FILEN|opensite.ocx
NEWPR|1715|ZyncosSpace
PRCAT|5
CLSID|{f0dc0cfe-d11a-489b-84c0-63748afaabf3}
DIREC|%programfiles%\zyncosspace\
AUTST|ZyncosMark
CLASS|CMCTL.CBrowserExt
CLASS|CMCTL.CURLTriggerProxy
RKSOF|Tmsitech
NEWPR|647|764 Dialer
PRCAT|8
NEWPR|956|7AdPower Dialer
PRCAT|8
CLSIA|{00000000-0000-0000-0000-000020030000}
CLSIA|{00000000-0000-0000-0000-000020040000}
CLSIA|{042eea26-2402-4e5a-b5bb-0fb445a5526e}
CLSIA|{0fcd5a05-bcec-4bb1-9ed3-88c289d87abb}
CLSIA|{2517f764-6f60-4add-8fcf-137e5b220ff6}
CLSIA|{261ee805-4893-45a3-8e9e-ad90914cb39a}
CLSIA|{35f59c80-c1f2-4eea-9981-686c7d5a9277}
CLSIA|{3b623d23-2757-4881-a01e-d560ebca5307}
CLSID|{3da4a3a4-06be-49e0-b8ba-03580903122b}
CLSIA|{4208564c-62f0-45e6-87de-0861d11c0613}
CLSIA|{4ae9e3bf-409d-4f61-9804-920968603919}
CLSIA|{4ef86fae-4fda-4b1a-a80f-811e0a5da08a}
CLSID|{5d647e9c-6b37-4636-9a78-dadb1eb93bdf}
CLSIA|{60efc337-15c2-4369-b2a0-3429b071d8b8}
CLSIA|{683dff0f-331f-44d2-b69b-46d7bfb58f32}
CLSIA|{706f3805-27d7-478d-80e5-e25d2bb030b3}
CLSIA|{8701e3b9-dc63-440b-83a1-80f27a4fcafa}
CLSIA|{8bea0789-fe58-4753-8a75-432fcd1a5705}
CLSIA|{970bf476-3cf2-4572-9ef9-4479e1591db8}
CLSIA|{9e98e84c-79e1-49c3-82eb-798fcd552efb}
CLSID|{ac86f549-28a6-4ac8-9c2c-0d52b4b1f5ec}
CLSIA|{ad0b8220-7da4-4c0a-8532-b25a9f631d3d}
CLSIA|{b1b7606a-d7b9-42a8-afa2-476308413211}
CLSIA|{bd092cd7-aa66-4ff6-8ce1-d4e01489ed2b}
CLSIA|{c7384a94-12ab-4798-9a63-67a9b24c993d}
CLSIA|{cdcbe0f1-d13a-4f86-a963-3a272d3aba7e}
CLSIA|{f1051f05-fbfa-48bd-8e45-f5d3bdc45d3d}
CLSIA|{f164ece9-e6df-4085-961c-083bd1809319}
CLSID|{f43e6264-7da7-45af-a90d-75534f0c6754}
CLSIA|{f9deab0b-ff3e-4d99-8698-9b535d164256}
CLSIA|{ffff0001-0002-101a-a3c9-08002b2f49fb}
CLSIA|{ffff0021-0002-101a-a3c9-08002b2f49fb}
AUTST|AdPopup
AUTST|AdUpdater
CLASS|VacPro.internazionale_ver11
CLASS|Vacpro.netherland_ver2
FILEN|internazionale_ver15.cab
NEWPR|2585|Absolu-trans
PRCAT|8
FILEN|absolu-trans.exe
NEWPR|583|AccessPlugin
PRCAT|8
CLSIA|{034cc2dc-3245-4b26-b5c7-7b8777739cb7}
CLSIA|{2b3ac84b-3128-45b4-bb8d-6cc9a42d24ec}
CLSIA|{42f2d240-b23c-11d6-8c73-70a05dc10000}
CLSIA|{d8efadf1-9009-11d6-8c73-608c5dc19089}
REGKE|HKEY_CLASSES_ROOT\AppID\exengd.EXE
CLASS|Exengd.DialerCon
RKSOF|DCon
RKSOF|webdialer
NEWPR|648|Aconti
PRCAT|8
CLSIA|{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}
CLSIA|{7589eee6-e336-11d4-8a7e-ee1d971d9b47}
AUTST|runwin32
CLASS|AcontiXControl
RKSOF|ALifestyle
FILEN|int179663.exe
NEWPR|2167|Active-X Dialer
PRCAT|8
CLSIA|{0f7bd988-96a9-4505-9997-19011055f07c}
CLSIA|{33bcb2bb-173d-163b-779b-33c13379504c}
CLSIA|{62c9173e-c4c3-43b9-82f2-3ddd51663b00}
CLSIA|{7dbfda8e-d33b-11d4-9269-00600868e56e}
CLSIA|{84b40160-54e0-4d2f-ac18-a6d31a9ac732}
CLSIA|{86eef11e-ff16-48ce-b1a2-474b663041a9}
CLSIA|{c56ce781-a6fc-4706-8b32-6eb4622155df}
CLSID|{cfbc1c51-d33c-11d4-9269-00600868e56e}
FILEN|gdnus208.exe
NEWPR|2575|Adh1_sexarea
PRCAT|8
DIREC|%programfiles%\montorgueil
DIREC|%userprofile%\Start Menu\Programs\HOT Dialer\
FILEN|%userprofile%\Start Menu\Latinas.lnk
NEWPR|1100|Adpower.b
PRCAT|8
CLSIA|{3e339d3c-4b12-4e8c-a529-9cc4beeafd4f}
CLSID|{7b6ff147-4e5a-4a2f-8789-84efc132849d}
CLSIA|{84bf9dc5-7bc8-4efd-
85b3-489c714f4fd1}
CLSIA|{91b9979b-c663-43a0-855e-df04025eb0a2}
CLSIA|{9ae283a5-df43-4c83-b6aa-7ebdbdb0204a}
CLSID|{e4870a7b-6c2f-42b9-9938-f6d729afc493}
CLSIA|{fbc59f54-80a2-4df5-a0ad-b2d3221c8b32}
RKSOF|ADPower
NEWPR|646|Adult Chat Dialer
PRCAT|8
CLSID|{022850cb-74fd-486d-8b1c-573ecfd599ad}
CLSIA|{2c1651ef-8827-11d6-91a2-00e02964e8e3}
CLSIA|{469843dd-ebb3-4661-b0a6-e6fe590240c9}
CLSIA|{6986a6cf-9d58-11d6-91c2-00e02964e8e3}
CLSIA|{8522f9b3-38c5-4aa4-ae40-7401f1bbc898}
CLSIA|{9dbafccf-592f-ffff-ffff-00608cec297c}
CLSID|{b5dd9a64-5c4b-4a48-be56-97c1a8f85708}
CLSIA|{ffff0017-0001-101a-a3c9-08002b2f49fb}
DIREC|%programfiles%\nog\
AUTST|addot.exe
AUTST|Lisa
AUTST|MSStartOptimizer
AUTST|RegCompres
AUTST|tibs3
CLASS|.htnw
CLASS|htnw File
RKSOF|nog
RKSOF|Pinfo
UINST|Lisa
FILEN|adult_chat.exe
FILEN|tibs3.exe
NEWPR|1971|Adult Dialer
PRCAT|8
CLSIA|{8f24de00-0d66-4f93-9405-3f21e97aee99}
CLSIA|{94118c19-b178-4e43-bbe8-0efdbb391bdb}
AUTST|HotSexy_Now
FILEN|esbadultinstaller.ocx
NEWPR|2418|Adult.LSDIALER
PRCAT|8
FILEN|%Systemdrive%\ecommerce\dialer.ini
NEWPR|1151|Adultoweb Dialer
PRCAT|8
CLSIA|{067d7797-04fc-42b1-92db-81fc6cd318fd}
CLSIA|{23273a1c-c870-43c4-a3e3-67dc98630ac6}
CLSIA|{a45f39dc-3608-4237-8f0e-139f1bc49464}
CLSIA|{c771b05e-e725-4516-97a5-4ce5eb163cfb}
DIREC|%ProgramFiles%\fist\
AUTST|NsUpdate
RKSOF|GlobalCS
FILEN|%UserProfile%\Desktop\fist.LNK
FILEN|%UserProfile%\Start Menu\Programs\fist.LNK
NEWPR|1228|All-In-One Telcom
PRCAT|8
CLSID|{da9a0b0f-9b7b-11d3-b8a4-00c04f79641c}
CLSID|{da9a0b1d-9b7b-11d3-b8a4-00c04f79641c}
CLSID|{da9a0b1f-9b7b-11d3-b8a4-00c04f79641c}
CLASS|hadate file
CLASS|nsupdatelite.nsupdatelitectrl
RKSOF|hotactiondating
UINST|hotactiondating
NEWPR|2578|Andlotsmore.com dialer
PRCAT|8
NEWPR|820|babetv
PRCAT|8
CLSIA|{30ce93ae-4987-483c-9abe-f2bd5301ab70}
NEWPR|2588|BlondeSalope
PRCAT|8
NEWPR|779|BTV Dialer
PRCAT|8
DIREC|%ProgramFiles%\BTV\
DIREC|%ProgramFiles%\Common Files\midaddle\
DIREC|%programfiles%\diallerprogram\
AUTST|breg
NEWPR|2615|CAX Dialer
PRCAT|8
CLSIA|{2048b51e-8d74-4762-82ce-b48cf545eeea}
NEWPR|2579|CazzoCulo
PRCAT|8
NEWPR|2159|Central-24 Dialer
PRCAT|8
CLSID|{000000aa-abba-0704-0b53-2c8830e9faec}
CLSID|{0f4a7b40-a295-11cf-a3a9-00a0c9034920}
CLSID|{c60bc918-abba-0704-0b53-2c8830e9faec}
CLSIA|{dcf96da0-ed33-40ff-b83e-ab7011c2ba7e}
NEWPR|614|CrossKirk
PRCAT|8
CLSID|{0d639e64-5c31-4313-b62a-1b4d99e2f284}
CLSID|{3cd945a2-e413-4956-b9d8-a67fb6a7cb66}
CLSID|{9d6addbf-8227-4d36-ae46-116afbdafca0}
CLSID|{d24a1963-9951-4153-a340-6648759eb77d}
FILEN|crosskirk.cab
NEWPR|2593|Cuty girls
PRCAT|8
CLASS|XEng019.XEng019Ctl
NEWPR|2590|Cytainment
PRCAT|8
CLSIA|{00000000-abba-0704-0b53-2c8830e9faec}
CLASS| IELoaderCtl.IELoaderCtl
NEWPR|2251|Dataline Dialer
PRCAT|8
FILEN|dbn1742.exe
NEWPR|1968|Dialer-S
PRCAT|8
CLSID|{6986a6c2-9d58-11d6-91c2-00e02964e8e3}
CLASS|Pagomaster.IntPagomaster
FILEN|pagomaster.dll
NEWPR|1303|dialer-shop
PRCAT|8
CLSID|{6814a9ef-fbf1-46b2-a46e-56b401079c26}
CLSIA|{9d0a9d98-5221-430a-a02d-76f0827c82d1}
CLSIA|{d7b59209-0ed9-4986-bd4a-527be836c6b2}
NEWPR|2258|Dialer.ASDPlugin
PRCAT|8
AUTST|ASDPLUGIN
RKSOF|ASDPLUGIN
FILEN|%USERPROFILE%\Desktop\Launch DerBiz.com.lnk
FILEN|%USERPROFILE%\Desktop\Launch globalEaccess.lnk
FILEN|%userprofile%\Desktop\SurfYa.com.lnk
FILEN|%USERPROFILE%\Start Menu\Launch DerBiz.com.lnk
FILEN|%USERPROFILE%\Start Menu\Launch globalEaccess.lnk
FILEN|%userprofile%\Start Menu\SurfYa.com.lnk
FILEN|%USERPROFILE%\Start Menu\Uninstall Launch DerBiz.com.lnk
FILEN|%USERPROFILE%\Start Menu\Uninstall Launch globalEaccess.lnk
FILEN|%userprofile%\Start Menu\Uninstall SurfYa.com.lnk
FILEN|%Windir%\system32\dsldbaccess.exe
FILEN|%Windir%\system32\Geaccess.exe
NEWPR|2876|Dialer.Baj
PRCAT|8
NEWPR|2727|Dialer.BNI
PRCAT|8
NEWPR|1840|Dialer.Intexusdial
PRCAT|8
DIREC|%userprofile%\Start Menu\Programs\- tattooworld -
DIREC|%userprofile%\Start Menu\Programs\- tbuyit -
DIREC|%userprofile%\Start Menu\Programs\- Template-Tempel -
DIREC|%userprofile%\Start Menu\Programs\- testedich -
DIREC|%userprofile%\Start Menu\Programs\- Textfun.de - Witze und Sprueche -
DIREC|%userprofile%\Start Menu\Programs\- TheHentai.NET Hentai Erotik
DIREC|%userprofile%\Start Menu\Programs\- TheHentai.NET Hentai Erotik -
DIREC|%userprofile%\Start Menu\Programs\- Tierbabys -
DIREC|%userprofile%\Start Menu\Programs\- Tierheime -
DIREC|%userprofile%\Start Menu\Programs\- Toprezpte24 -
DIREC|%userprofile%\Start Menu\Programs\- Trilian-de -
DIREC|%userprofile%\Start Menu\Programs\- Tuerkei -
DIREC|%userprofile%\Start Menu\Programs\- TURKGAYS -
DIREC|%userprofile%\Start Menu\Programs\- UmsatzSteigern.de -
DIREC|%userprofile%\Start Menu\Programs\- Vornamen-Fundus -
DIREC|%userprofile%\Start Menu\Programs\- Wetter-Basis -
DIREC|%userprofile%\Start Menu\Programs\- witzealarm -
DIREC|%userprofile%\Start Menu\Programs\- Wohnung -
DIREC|%userprofile%\Start Menu\Programs\- XP-Antispy.de -
RKSOF|Intexus
RKSOF|IntexusDial
UINST|1md.de
FILEN|%userprofile%\Desktop\1md.de.lnk
FILEN|%userprofile%\Desktop\Anti-Report anti-report.lnk
FILEN|%userprofile%\Desktop\Counter.de counterde.lnk
FILEN|%userprofile%\Desktop\Fahrschule fahrschule.lnk
FILEN|%userprofile%\Desktop\GifProfi gifprofi.lnk
FILEN|%userprofile%\Desktop\gifsworld gifsworld.lnk
FILEN|%userprofile%\Desktop\Girlscam girlscam.lnk
FILEN|%userprofile%\Desktop\GrussProfi grussprofi.lnk
FILEN|%userprofile%\Desktop\HENTOON.DE hentai-de.lnk
FILEN|%userprofile%\Desktop\IQ Welt iqwelt.lnk
FILEN|%userprofile%\Desktop\iqtest iqtest.lnk
FILEN|%userprofile%\Desktop\lebenslauf.de lebenslauf-de.lnk
FILEN|%userprofile%\Desktop\Manga6.de manga6-de.lnk
FILEN|%userprofile%\Desktop\Megastars megastars.lnk
FILEN|%userprofile%\Desktop\Meine Seite meineseite.lnk
FILEN|%userprofile%\Desktop\Monster Vorlagen monstervorlagen.lnk
FILEN|%userprofile%\Desktop\MP3-Legal mp3-legal.lnk
FILEN|%userprofile%\Desktop\Neandertaler neandertaler.lnk
FILEN|%userprofile%\Desktop\neueinrichten.de neueinrichten-de.lnk
FILEN|%userprofile%\Desktop\Online Diaet onlinediaet.lnk
FILEN|%userprofile%\Desktop\Referate referate.lnk
FILEN|%userprofile%\Desktop\ReporteMafia.de reportemafia-de.lnk
FILEN|%userprofile%\Desktop\Reptilien.AG reptilien-ag.lnk
FILEN|%userprofile%\Desktop\Rezepte.AG rezepte-ag.lnk
FILEN|%userprofile%\Desktop\Rezeptsammlung.com rezeptsammlung-com.lnk
FILEN|%userprofile%\Desktop\Routenplaner Profi routenplanerprofi.lnk
FILEN|%userprofile%\Desktop\Sagen sagen.lnk
FILEN|%userprofile%\Desktop\schei1 schei1.lnk
FILEN|%userprofile%\Desktop\Schoener werden schoenerwerden.lnk
FILEN|%userprofile%\Desktop\schulstadt schulstadt.lnk
FILEN|%userprofile%\Desktop\sexworld sexworld.lnk
FILEN|%userprofile%\Desktop\Smilie-Fabrik smilie-fabrik.lnk
FILEN|%userprofile%\Desktop\Spasspilot.de spasspilot-de.lnk
FILEN|%userprofile%\Desktop\Spieleindex spieleindex.lnk
FILEN|%userprofile%\Desktop\Sprueche.de sprueche-de.lnk
FILEN|%userprofile%\Desktop\Supergames supergames.lnk
FILEN|%userprofile%\Desktop\Taroskop.de taroskop-de.lnk
FILEN|%userprofile%\Desktop\Tattoo Mania tattoomania.lnk
FILEN|%userprofile%\Desktop\tattoopalace tattoopalace.lnk
FILEN|%userprofile%\Desktop\tbuyit tbuyit.lnk
FILEN|%userprofile%\Desktop\Template-Tempel template-tempel.lnk
FILEN|%userprofile%\Desktop\testedich testedich.lnk
FILEN|%userprofile%\Desktop\Textfun.de - Witze und Sprueche textfun-de.lnk
FILEN|%userprofile%\Desktop\TheHentai.NET Hentai Erotik thehentai-net.lnk
FILEN|%userprofile%\Desktop\Tierbabys tierbabys.lnk
FILEN|%userprofile%\Desktop\Toprezpte24 toprezpte24.lnk
FILEN|%userprofile%\Desktop\Trilian-de trilian-de.lnk
FILEN|%userprofile%\Desktop\Vornamen-Fundus vornamen-fundus.lnk
FILEN|%userprofile%\Desktop\XP-Antispy.de xp-antispy-de.lnk
FILEN|%userprofile%\Recent\Intexusdial.cc.lnk
FILEN|%userprofile%\Start Menu\Programs\- GifProfi -\GifProfi gifprofi.lnk
FILEN|%userprofile%\Start Menu\Programs\- gifsworld -\gifsworld gifsworld.lnk
FILEN|%userprofile%\Start Menu\Programs\- Girlscam -\Girlscam girlscam.lnk
FILEN|%userprofile%\Start Menu\Programs\- Megastars -\Megastars megastars.lnk
FILEN|%userprofile%\Start Menu\Programs\- Meine Seite -\Meine Seite meineseite.lnk
FILEN|%userprofile%\Start Menu\Programs\- Monster Vorlagen -\Monster Vorlagen monstervorlagen.lnk
FILEN|%userprofile%\Start Menu\Programs\- Neandertaler -\Neandertaler neandertaler.lnk
FILEN|%userprofile%\Start Menu\Programs\- neueinrichten.de -\neueinrichten.de neueinrichten-de.lnk
FILEN|%userprofile%\Start Menu\Programs\- Online Diaet -\Online Diaet onlinediaet.lnk
FILEN|%userprofile%\Start Menu\Programs\- Referate -\Referate referate.lnk
FILEN|%userprofile%\Start Menu\Programs\- ReporteMafia.de -\ReporteMafia.de reportemafia-de.lnk
FILEN|%userprofile%\Start Menu\Programs\- Reptilien.AG -\Reptilien.AG reptilien-ag.lnk
FILEN|%userprofile%\Start Menu\Programs\- Rezepte.AG -\Rezepte.AG rezepte-ag.lnk
FILEN|%userprofile%\Start Menu\Programs\- Rezeptsammlung.com -\Rezeptsammlung.com rezeptsammlung-com.lnk
FILEN|%userprofile%\Start Menu\Programs\- sexworld -\sexworld sexworld.ln
FILEN|%userprofile%\Start Menu\Programs\- sharing.ag -\sharing.ag share-dialer.lnk
FILEN|%userprofile%\Start Menu\Programs\- Smiley Castle -\Smiley Castle smileycastle.lnk
FILEN|%userprofile%\Start Menu\Programs\- TheHentai.NET Hentai Erotik -\TheHentai.NET Hentai Erotik thehentai-net.lnk
FILEN|2da45.exe
FILEN|alternativ-heilung.com ahm-10056.lnk
FILEN|beauty[schoenerwerden,1].exe
FILEN|bpmk.dat
FILEN|cocktails[ccp-10097,de].exe
FILEN|gifsworld[gwd-10927,de].exe
FILEN|hausaufgaben[hun-10002,de].exe
FILEN|hausaufgaben[hun-10222,de].exe
FILEN|horoskop_erstellen[aie-10070,de].exe
FILEN|lehrstellen[lhs-10004,de].exe
FILEN|liebesbriefe[lbi-10023,de,start].exe
FILEN|pflanzen[pla-10006,de].exe
FILEN|routenplanerag.exe
FILEN|sagen.exe
FILEN|satanismus.exe
FILEN|satfrequenzen.exe
FILEN|scheisse[schei1,1].exe
FILEN|schulstadt-1.exe
FILEN|schulstadt-2.exe
FILEN|schulstadt-3.exe
FILEN|schulstadt-4.exe
FILEN|schulstadt-5.exe
FILEN|schulstadt-6.exe
FILEN|schulstadt-7.exe
FILEN|schulstadt.exe
FILEN|schwanger.exe
FILEN|setup(1-1md-0-0-,us)-1.exe
FILEN|sexworld[sexworld,1].exe
FILEN|sharing-ag-1.exe
FILEN|sharing-ag.exe
FILEN|slowenien.de.exe
FILEN|smiley[smileycastle,1].exe
FILEN|smiley[syc-10008,1].exe
FILEN|smilie-fabrik.exe
FILEN|sms-stadt-1.exe
FILEN|sms-stadt-2.exe
FILEN|sms-stadt-3.exe
FILEN|sms-stadt.exe
FILEN|sms-tool.exe
FILEN|songtexte[sgx-10001,1].exe
FILEN|songtextzone-1.exe
FILEN|songtextzone-2.exe
FILEN|songtextzone-4.exe
FILEN|spass4u[s4e-10020,1].exe
FILEN|spasspilot-1.exe
FILEN|spicktricks[ree-10323,de].exe
FILEN|spieledownload[ssg-10001,1,a63e].exe
FILEN|spieleindex[spieleindex,1].exe
FILEN|spiele_runterladen[geg-10066,1].exe
FILEN|sprueche.exe
FILEN|stammbaum.de.exe
FILEN|starfuck.exe
FILEN|stars-nackt.exe
FILEN|sternzeichen[szn-10011,de].exe
FILEN|straflos[anti-report,1].exe
FILEN|suchmaschinen-1.exe
FILEN|supergames[supergames,1].exe
FILEN|taroskop.exe
FILEN|tattoo-1.exe
FILEN|tattoo-2.exe
FILEN|tattoopalace-11.exe
FILEN|tattoos[tod-10109,de].exe
FILEN|tattoos[tod-10133,1].exe
FILEN|tattoovorlagen-de[toe-10362,1]-2.exe
FILEN|tattoo[tattoomania,1].exe
FILEN|tattoo[toe-10082,1].exe
FILEN|template-tempel.exe
FILEN|tests[iqwelt,1].exe
FILEN|test[teh-10116,de,start4].exe
FILEN|tierbabys[tierbabys,1].exe
FILEN|toprezept.exe
FILEN|trilian[trilian-de,1].exe
FILEN|tuerkei.exe
FILEN|turkgays[tks-10001,1].exe
FILEN|umsatzsteigern[uee-10001,1].exe
FILEN|valueradio-1.exe
FILEN|vornamen.exe
FILEN|vornamen[vnf-10049,1].exe
FILEN|vornamen[vnf-10103,1].exe
FILEN|wetter-basis-1.exe
FILEN|wetter-basis.exe
FILEN|witzealarm.exe
FILEN|witze[counterde,1].exe
FILEN|wohnung.exe
NEWPR|2281|Dialer.ks
PRCAT|8
CLSID|{3eb94323-0856-4479-aa22-d81bbfeea91e}
CLSID|{6bc36767-3fcc-4948-8a13-703f887a3e87}
CLSIA|{e53458d2-5a83-4bd1-8de2-eeebe73bab49}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ccaccess.dll
CLASS|Ccaccess.CheckControl
NEWPR|2714|Dialer.Maxd
PRCAT|8
FILEN|maxd641.exe
NEWPR|2119|Dialer.Mostrar
PRCAT|8
CLSID|{095c0db4-fea6-440e-8dfc-00fc53ac827d}
CLSID|{4fc63700-2093-4ad2-8d37-3b3d86d9c940}
CLSID|{5bf0ce3e-61d2-4a7b-baa3-0c4667a9563d}
CLSIA|{88c51e90-8e9c-4c96-8a45-574d88b63faf}
CLSIA|{ffff0003-0001-101a-a3c9-08002b23e0cc}
CLSIA|{ffff0003-0001-101a-a3c9-08002b23e0cd}
REGKE|HKEY_CURRENT_USER\PTPSA32.PTPSAWeb
AUTST|Dialer
CLASS|PTPSA32.PTPSAWeb
FILEN|%windir%\Downloaded Program Files\msa64chk.inf
NEWPR|3532|Dialer.Qi
PRCAT|8
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Emitt
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform , ADVPLUGIN|K115|165|S-866237264|dialno
AUTST|auoie
IEZON|nodialup.name
IEZON|whatsnew.name
FILEN|syslcznp.exe
NEWPR|2609|Dialer.Sfonditalia
PRCAT|8
IEZON|realarea.biz
NEWPR|2877|Dialer.XD
PRCAT|8
NEWPR|2557|DialerActiveX
PRCAT|8
CLSID|{660b7669-1a16-4864-ac91-8ecbbe7de93f}
CLSID|{8e224ed3-c09f-4ff9-9ace-883d99498f26}
CLSID|{aee9cc65-40f3-4f61-b919-a728bc526d58}
CLSID|{b27bf58e-619c-43f6-8f2a-e4c6428b5245}
CLASS|DIALERACTIVEX.DialeractivexCtrl
NEWPR|406|DialerFactory
PRCAT|8
NEWPR|473|DialerOffline
PRCAT|8
CLSID|{1773b696-b019-4fc1-9eed-b1c7f925f56a}
CLSID|{20270406-63ad-4c7e-ae8d-bb632e508ace}
CLSID|{271d7d74-8e6d-4e6c-86f5-66c064cfb74d}
CLSID|{89161220-a3d9-464f-848c-4ebe0546697d}
CLSID|{a8882720-e26c-4073-8b8a-981d32882af7}
CLSID|{b0acf771-f0f7-461f-bef3-5b1a3ba42f51}
CLSID|{cabd7099-6b04-471d-8371-9fde9c2e6bea}
CLSIA|{ceb29da4-7afa-4f24-b3cd-17351d590df0}
FILEN|dialeroffline.dll
NEWPR|821|DialXS
PRCAT|8
CLSIA|{9b4aa442-9ebf-11d5-8c11-0050da4957f5}
CLASS|DialXS.DialXSCtl
NEWPR|2861|E-nrgyPlus Dialer
PRCAT|8
DIREC|%allusersprofile%\Start Menu\Programs\E-nrgyPlus\
DIREC|%programfiles%\E-nrgyPlus\
AUTST|E-nrgyPlus
NEWPR|2514|Edipole
PRCAT|8
CLASS|WebInstall.WWWInstall
NEWPR|2829|Eocha
PRCAT|8
CLSIA|{2f6c63df-48ad-44c3-a761-7fb53ecf064a}
CLSIA|{3a4dcd02-a451-4799-9e1c-ac0d4f769a97}
CLSIA|{3f5e67e1-81e6-4487-bf6f-07941a080bab}
CLSIA|{3fa96320-481c-4af4-819a-968a6426928e}
CLSIA|{4360e841-fe3e-427f-98dc-7abc8ace6665}
CLSIA|{4d4c0269-8303-4448-80dc-a3de34bc5374}
CLSIA|{5c626a4f-28a7-4a29-9ec8-6be20fc70424}
CLSIA|{72e0f892-b9f1-451d-95a3-2e6c1f45c0dd}
CLSIA|{73b9a791-ba9e-418a-b5a4-948b63be04f7}
CLSID|{8431328a-1050-42a8-a615-809f40d3037d}
CLSID|{8dab5c8c-c784-4651-84f7-b6c9f4eec53d}
CLSIA|{96966b7c-ca72-4928-895b-1c2f0e5302a9}
CLSIA|{9caee012-5dff-11db-8373-b622a1ef5492}
CLSIA|{9f54bf10-c88e-43fd-aa9e-16bf45747c72}
CLSIA|{9f5bb9e1-31ae-4a13-8734-15ced0f60a3d}
CLSIA|{ca654d30-99f2-4dd1-b58c-767e2bb862ff}
CLSIA|{ea5b2f8a-2094-47a1-adc5-373e93eaf936}
CLSIA|{ea8804ce-a2f0-4773-89b8-1e5168a1d8d7}
CLSIA|{eb5cdbc6-dba4-48bc-b888-5e2cff9df3cd}
CLSIA|{f40f43f6-890c-479d-a996-306123662084}
DIREC|%ProgramFiles%\SmilEmail\
AUTST|ciakaisen.exe
AUTST|lateshow.exe
AUTST|MicrosoftFirewall
AUTST|MSGlobal
AUTST|MSMalwareKit
AUTST|SmilEmail
AUTST|StopPhish
AUTST|wke.exe
CLASS|ActiveXCOM.myActiveXCOM
CLASS|XBTB08814.IEToolbar
RKSOF|ADWhere Component
RKSOF|Coprocefalo
RKSOF|XBTB08814
UINST|XBTB08814.XBTB08814Toolbar
FILEN|%USERPROFILE%\My Documents\My Music\PrintHood\Canon BJC su Giorgia.lnk
FILEN|%USERPROFILE%\My Documents\My Music\The Clash.lnk
FILEN|%USERPROFILE%\Start Menu\messaggio3.exe
FILEN|%USERPROFILE%\Start Menu\Vocabolario.lnk
IEZON|cds.zangocash.com
IEZON|ciritorno.biz
IEZON|content.licenseacquisition.org
IEZON|cywanstorage.biz
IEZON|defaultbar.com
IEZON|licenseacquisition.org
IEZON|melagodo.biz
IEZON|pergentina.biz
IEZON|playmore.biz
IEZON|preferiti-windows.com
IEZON|static.zangocash.com
IEZON|terzodesiderio.biz
IEZON|www.acquadirose.com
IEZON|www.ciritorno.biz
IEZON|www.defaultbar.com
IEZON|www.forteforte.com
IEZON|www.melagodo.biz
IEZON|www.nanobyte.biz
IEZON|www.pergentina.biz
IEZON|www.phishingfix.biz
IEZON|www.playmore.biz
IEZON|www.popup-freesex-adv.biz
IEZON|www.preferiti-windows.com
IEZON|www.ricercadoppia.com
IEZON|www.scalalap.com
IEZON|www.sextriere.com
IEZON|www.smilemail.biz
IEZON|www.super-videochat-community.biz
IEZON|www.terzodesiderio.biz
IEZON|www.tuttaqualita.com
IEZON|www.umts-gprs-mondo-telefonino-cellulare.biz
IEZON|www.virgilio.in
IEZON|www.what-you-want.biz
NEWPR|2671|Eroskop Dialer
PRCAT|8
AUTST|AntyVirKS
NEWPR|784|EroticAccess
PRCAT|8
CLSIA|{1230cb21-c88d-11cf-b347-000000000000}
CLSIA|{73f0fd85-bd47-4a95-86d1-de38860462c1}
NEWPR|2402|FairTale
PRCAT|8
CLSID|{adb5c6a6-4595-4038-859b-d213969892a3}
CLSID|{e2bba7ac-2347-4761-af7a-0dca61355d53}
CLSID|{e5502c44-565e-4897-819f-c6abae1f89fb}
DIREC|%systemdrive%\fairtale\
CLASS|.ft0
CLASS|Fairtale
CLASS|fairtale.Class1
NEWPR|1798|FairyTale
PRCAT|8
CLSIA|{940ec490-8c20-4360-a725-1f44984933df}
CLSIA|{99e79790-2b09-11d6-8c73-0800460222f0}
NEWPR|2582|FanAlizee
PRCAT|8
NEWPR|2755|FanNolwenn
PRCAT|8
FILEN|%USERPROFILE%\Desktop\FanNolwenn.lnk
FILEN|%USERPROFILE%\Start Menu\FanNolwenn.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\HOT Dialer\FanNolwenn.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\HOT Dialer\Uninstall FanNolwenn.lnk
NEWPR|2591|FanSalma
PRCAT|8
NEWPR|788|FreeLoad
PRCAT|8
NEWPR|2528|Fundial
PRCAT|8
CLSID|{1f20cf42-b381-4181-8c2a-a389b1022e6e}
CLSID|{703e919d-28c9-4491-8d01-8964e47bbbba}
DIREC|%SystemDrive%\dialerfun\
CLASS|Dialer.Class1
NEWPR|2475|Gamesplayground
PRCAT|8
CLSIA|{fde6b956-b80a-4578-9a10-4c24609412f1}
NEWPR|679|GlobalDialer
PRCAT|8
CLSIA|{05d087e7-51bd-3f5b-7bb5-0c6a120fc11a}
CLSIA|{11111111-1111-1111-1111-511111193457}
CLSIA|{11111111-1111-1111-1111-511111193458}
CLSIA|{11111111-1111-1111-1111-611111193457}
CLSIA|{11111111-1111-1111-1111-611111193458}
CLSIA|{11111111-1111-1111-1114-511155593469}
CLSID|{12c94089-40ef-4885-860a-6cdd3e138a20}
CLSIA|{22222222-2222-2222-4444-566661888858}
CLSIA|{23232323-2323-2323-2323-232323231122}
CLSIA|{23232323-2323-2323-2323-232323291122}
CLSIA|{2dc2b96e-1748-11d5-94e4-006008a4ed7f}
CLSIA|{38545c2a-03cd-42c3-bc62-c537a6d5a8f6}
CLSIA|{413a0886-cbc2-4cbe-bbc7-3b423eb15383}
CLSID|{5d945e9a-dc10-4670-83eb-99daa616628a}
CLSIA|{5f944a91-2888-1cef-ffff-7b632dba7c98}
LSIA|{6a5081c6-d0f7-5f22-467f-40610638bfca}
CLSIA|{753c42af-4e2e-5334-f69c-45732649b667}
CLSIA|{7cd66bd1-e395-0425-146c-46cd022dc162}
CLSIA|{861fda2a-2b57-4bda-8b8b-305c9d5d8604}
CLSIA|{97b79133-88f0-45f0-8d57-0f2ef27d9c66}
CLSIA|{b3aa2f6b-6baf-11d3-ba05-00c0f0322972}
CLSIA|{b94b4225-e02e-4d3f-badb-026f1e2f3ad7}
CLSIA|{d22ac3ef-b7d8-11d5-a281-005056bf0101}
CLSIA|{d52d92f2-3650-439c-aa18-03ee4f6859de}
CLSIA|{deda29ca-3653-456e-b4c9-63a5d85d35d6}
CLSIA|{faff0003-0a01-121a-a1c9-08032b23e0cc}
CLSIA|{ff3f0f03-0f01-131a-a3f9-08f02b23e0cc}
CLSIA|{fffb1d8b-88d6-4c91-bb62-378625e8c73e}
CLSIA|{ffff0018-0001-101a-a3c9-08002b2f49fb}
DIREC|%ProgramFiles%\GlobalDialer\
AUTST|sws.exe
AUTST|w32sup
CLASS|Gxbplug.plug
CLASS|Loader.LoaderObj
CLASS|OLibrary.IEPlugIn
CLASS|Suchspur.SuchspurObj
RKSOF|Gxb
UINST|GlobalDialer
FILEN|gd-ff_be.exe
FILEN|gd-ff_us.exe
FILEN|gdnca167.exe
FILEN|globaldialer.cab
FILEN|olibrary.dll
NEWPR|2512|GoIn Direct Dialer
PRCAT|8
NEWPR|645|Hacker Spider
PRCAT|8
DIREC|%windir%\coder
UINST|Exclusiver Bereich
FILEN|%userprofile%\Desktop\Exclusiver Bereich.lnk
FILEN|%userprofile%\Start Menu\Programs\Exclusiver Bereich.lnk
FILEN|hacker spider.exe
NEWPR|709|Haldex
PRCAT|8
DIREC|%programfiles%\HaldexLtd\
NEWPR|407|HighSpeed Connector
PRCAT|8
FILEN|123-sexkino.exe
FILEN|aktgirls.exe
FILEN|aktshow.exe
FILEN|amateur-hardcore-sex.exe
FILEN|analorgasmus.exe
FILEN|analxxx.exe
FILEN|babesex.exe
FILEN|begleitung-online.exe
FILEN|berlin-erotik.exe
FILEN|betnaker.exe
FILEN|bigbusen.exe
FILEN|bumsmich.exe
FILEN|bundesligagirls.exe
FILEN|busencam.exe
FILEN|busenline.exe
FILEN|busenshow.exe
FILEN|busentreff.exe
FILEN|busenweb.exe
FILEN|camcontrol.exe
FILEN|casarossa.exe
FILEN|city-girls.exe
FILEN|clickfick.exe
FILEN|computersex.exe
FILEN|cyber-angels.exe
FILEN|cybererotiva.exe
FILEN|debabes.exe
FILEN|degirls.exe
FILEN|deutsch.exe
FILEN|devotelust.exe
FILEN|disnex.exe
FILEN|donnavargas.exe
FILEN|dream-sex.exe
FILEN|e-kontakte.exe
FILEN|ecsfun.exe
FILEN|ero-world.exe
FILEN|eroclick.exe
FILEN|eroklick.exe
FILEN|erophone.exe
FILEN|eroplanet.exe
FILEN|erotic-news.exe
FILEN|eroticenter.exe
FILEN|eroticliveshow.exe
FILEN|erotik-news.exe
FILEN|euromodels2.exe
FILEN|fickclick.exe
FILEN|fickenonline.exe
FILEN|fickklick.exe
FILEN|fickline.exe
FILEN|fickschule.exe
FILEN|ficksie.exe
FILEN|fussballgirls.exe
FILEN|germany.exe
FILEN|gina-wild-sex.exe
FILEN|girls.exe
FILEN|girlsbesuch.exe
FILEN|girlshotel.exe
FILEN|girlstalk.exe
FILEN|glas-haus.exe
FILEN|hardcore-live-sex.exe
FILEN|hooters.exe
FILEN|hotbunny.exe
FILEN|hotelbesuch.exe
FILEN|hotelgirls.exe
FILEN|hotpower.exe
FILEN|hotvot.exe
FILEN|hotwied.exe
FILEN|klickfick.exe
FILEN|kontaktechat.exe
FILEN|lesbenhaus.exe
FILEN|life-girl.exe
FILEN|lifegirl.exe
FILEN|live-studio.exe
FILEN|livechatcam.exe
FILEN|livephone.exe
FILEN|livesex.exe
FILEN|livesexkanal.exe
FILEN|liveshow.exe
FILEN|lovephone.exe
FILEN|lucky-punch.exe
FILEN|macronedia.exe
FILEN|maxxcafe.exe
FILEN|meetboys.exe
FILEN|meinecam.exe
FILEN|moesenhaus.exe
FILEN|mytits.exe
FILEN|nacktshow.exe
FILEN|nudeliveshow.exe
FILEN|online-begleitung.exe
FILEN|online-escort.exe
FILEN|orgasmusbilder.exe
FILEN|orgasmusline.exe
FILEN|orgasmuslive.exe
FILEN|orgasmusparty.exe
FILEN|orgasmusvideo.exe
FILEN|osnastrip.exe
FILEN|pagesex.exe
FILEN|pam.exe
FILEN|peep-show-girls.exe
FILEN|persiankitti.exe
FILEN|persianklitty.exe
FILEN|phonegirl.exe
FILEN|phythom.exe
FILEN|playboobs.exe
FILEN|playgal.exe
FILEN|playmoesen.exe
FILEN|playmuschi.exe
FILEN|porncam.exe
FILEN|porno-porno-sex-sex.exe
FILEN|pornodelux.exe
FILEN|pornomoesen.exe
FILEN|privatbesuch.exe
FILEN|pussygeil.exe
FILEN|pussyhaus.exe
FILEN|redlightgirls.exe
FILEN|rotlichtchat.exe
FILEN|rotlichtgirls.exe
FILEN|rotlichtline.exe
FILEN|rotlichtshow.exe
FILEN|schulsex.exe
FILEN|sex-erotik-show.exe
FILEN|sex-live-chat.exe
FILEN|sex-porno-show.exe
FILEN|sex-rooms.exe
FILEN|sex-sex-porno-porno.exe
FILEN|sex-sex-sex-pussy.exe
FILEN|sex-tabulos.exe
FILEN|sexcall.exe
FILEN|sexdominanz.exe
FILEN|sexevents.exe
FILEN|sexfetish.exe
FILEN|sexillusion.exe
FILEN|sexkarussell.exe
FILEN|sexkeller.exe
FILEN|sexme.exe
FILEN|sexmich.exe
FILEN|sexpicturegallery.exe
FILEN|sexroulette.exe
FILEN|sexschule.exe
FILEN|sextacy.exe
FILEN|sexycamera.exe
FILEN|smutlamd.exe
FILEN|soos.exe
FILEN|strapsshow.exe
FILEN|strichgirls.exe
FILEN|strip-eonline.exe
FILEN|strip-girls.exe
FILEN|stripcan.exe
FILEN|striplime.exe
FILEN|stripline.exe
FILEN|strippenonline.exe
FILEN|stripschule.exe
FILEN|studiosex.exe
FILEN|suendenspiele.exe
FILEN|teenmail.exe
FILEN|telestrip.exe
FILEN|the-sweets.exe
FILEN|tittengeil.exe
FILEN|tittenline.exe
FILEN|tittenseite.exe
FILEN|tittenspiele.exe
FILEN|tittenweb.exe
FILEN|tittenwelt.exe
FILEN|travelsex24.exe
FILEN|venusgirls.exe
FILEN|venusphone.exe
FILEN|victoriasecreet.exe
FILEN|videochatcam.exe
FILEN|viona.exe
FILEN|vollbusicam.exe
FILEN|wichsen.exe
FILEN|wild-sex.exe
FILEN|xxxphone.exe
NEWPR|1238|Holystic
PRCAT|8
CLSIA|{037b3d58-d14a-4c41-bdfd-bd779b0b97ba}
CLSIA|{03c543a1-c090-418f-a1d0-fb96380d601d}
CLSIA|{0733b8f9-8b52-4693-a9fa-829e12d27f78}
CLSIA|{0873478e-e67a-4876-b0a9-9a36d3ab3602}
CLSIA|{0cb2bd5a-7a80-4ba9-b49a-02dc51144bdf}
REGKE|HKEY_CLASSES_ROOT\HOL3_VXIEWER.FULL.1
REGKE|HKEY_CLASSES_ROOT\HOL_PRELOAD.FULL.1
NEWPR|408|HotActionDating
PRCAT|8
FILEN|hotactiondating-uninstall.exe
FILEN|hotactiondating.exe
FILEN|nsi145.exe
NEWPR|2583|Hot_Pleasure
PRCAT|8
REGKE|HKEY_CURRENT_USER\Software\SiteIcons\Dialers
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pmxy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-pmxy
AUTST|LiveSexCams
CLASS|pmxy File
UINST|LiveSexCams
FILEN|%USERPROFILE%\Desktop\LiveSexCams.lnk
NEWPR|771|Ibero Dialer
PRCAT|8
CLSIA|{19e0f68f-c0ef-4241-b876-a3d646995895}
CLSIA|{1d7532ce-995b-40f2-8c17-2e01af16ffac}
CLSIA|{2c0f2aea-3a9b-46db-a7be-80ff329e415d}
CLSIA|{571c345e-7356-444b-a4e2-1b6442f96ebc}
CLSIA|{b15108aa-d8d0-480d-b535-07e18d6549a8}
CLSIA|{fb8d70e2-554a-4c75-90be-66c302367e0d}
FILEN|ppremiuminternacional.dll
NEWPR|432|IBS
PRCAT|8
FILEN|gratis-sex-crack.exe
FILEN|traumdate.exe
NEWPR|456|IEAccess
PRCAT|8
CLSIA|{0594af7e-573b-40df-8165-e47ab2eaefe8}
CLSIA|{11f1d260-129e-4eb7-b37e-57e3d97a3df1}
CLSIA|{1a9ec776-942a-4a51-8cd6-0dd9c25ed05b}
CLSIA|{1d2dca0d-b30f-40ad-9690-087105f214ec}
CLSIA|{1eb17d1c-141d-4d9d-91cb-24d99215851d}
CLSIA|{2abe804b-4d3a-41bf-a172-304627874b45}
CLSIA|{2aeeac34-fd74-4142-b891-4b05c0c03c87}
CLSID|{2f668a6d-2ec7-4e3a-a485-819e210738d6}
CLSID|{4209b4c1-1295-4908-9312-a53c036eb3cd}
CLSIA|{469c7080-8ec8-43a6-ad97-45848113743c}
CLSIA|{486e48b5-abf2-42bb-a327-2679df3fb822}
CLSIA|{50ad557e-3426-41fd-afdd-2af39bb1c387}
CLSID|{62bfaec2-82a5-4117-a98b-fea89413d924}
CLSIA|{6aa93df6-6757-4338-9087-f7601de18402}
CLSIA|{71cbdcd9-0830-4470-a890-35d364da352c}
CLSID|{7699aef9-f83a-44fa-b374-aa02cedf247d}
CLSIA|{77ef6dbf-3929-4081-af2e-178d387e211c}
CLSIA|{79733e69-6e1c-4682-bdf5-710d217a4125}
CLSID|{81c2f7f3-f930-455e-9aa5-0876d387c787}
CLSID|{83f0d6aa-cd15-46b5-aa4e-bdb506b4ae53}
CLSIA|{8b936702-c234-40d0-b69c-a2f669a33978}
CLSID|{901166a5-f137-4b27-bc4c-ca611debdced}
CLSIA|{946b0485-8f8c-4c35-a6e7-d2115e3b0b4f}
CLSIA|{94f5dcb7-816c-4b94-a2c1-856c6e323c5b}
CLSIA|{99ff4323-e68c-46dc-8f48-1f79a7005336}
CLSIA|{9c020689-fa7d-4d8d-be7e-dc263791cb29}
CLSIA|{9ef4e3e4-2f1e-472e-9ff2-2670ea5c42d9}
CLSIA|{a02780c3-7f77-4e28-855b-28890f3cf37a}
CLSIA|{afcf364f-f730-4b1e-b2d5-80f9172fbc44}
CLSIA|{b843da96-2b2d-447e-90ab-b92929aa11af}
CLSIA|{bd3653e4-884b-43c4-970b-670802501b7f}
CLSIA|{be5a7132-329f-4319-b781-2a83bfe51534}
CLSIA|{c20eb175-0dd0-4979-a994-1f0dba69f627}
CLSIA|{c9269872-e3d6-4811-8e5e-835ca8cbd0b3}
CLSIA|{caaf9105-a683-4ed1-89cc-18f6d194dd84}
CLSIA|{cdd8bade-b4c8-4e97-84b4-1dc9abad3ef3}
CLSIA|{cefb7b49-9652-464f-8afd-a577c0500f39}
CLSIA|{cf5f84eb-d3fc-4f98-be3b-f5b56b962ced}
CLSIA|{d8b94e9a-a34b-4253-bf48-c7cb7f2cfdb0}
CLSIA|{eeeca057-ad0f-44a7-8be5-8634cedbdbd1}
CLSIA|{f513e3da-5579-4981-8abc-99e411893c3d}
CLSIA|{f72bc3f0-6c20-4793-9dda-258589d8a907}
CLASS|egdhtml.egdialhtml
CLASS|eghtmldialer.htmldialer
CLASS|IEAccess2.IEDial
RKSOF|DIALPASS
RKSOF|egdhtml
RKSOF|egroup
FILEN|egdhtml_1015.dll
FILEN|egdhtml_1017.dll
FILEN|egdhtml_1020.dll
FILEN|egdhtml_1021.dll
FILEN|egdhtml_1023.dll
FILEN|egdhtml_1024.dll
FILEN|egdhtml_1025.dll
FILEN|egdhtml_1026.dll
FILEN|egdhtml_1027.dll
FILEN|egdhtml_1029.dll
FILEN|eghtmldialer.dll
FILEN|ieaccess2.cab
FILEN|ieaccess2.dll
FILEN|iedisco.exe
FILEN|nethv32_en_xp.cab
NEWPR|817|Instant-Access
PRCAT|8
CLSIA|{01be5bd7-b2dd-48b3-a759-59265a91e787}
CLSIA|{04ccff26-7d52-4e42-bf6a-f8ece0896eb7}
CLSIA|{04f414e9-e352-4bc3-963d-7bfe5a5f31a9}
CLSIA|{07c9cfc7-de33-4a0c-9ffb-cdfba843b157}
CLSIA|{0d1011b3-89c8-4f8e-8693-bb970e2e81e0}
CLSIA|{0da910bc-6919-489e-b584-d9a4aac7b8de}
CLSIA|{15d0e439-4e58-45e1-a9c1-0b1b16749a3c}
CLSIA|{1604df98-d1a5-44fe-844a-98d6fd0518d0}
CLSIA|{17bfc8da-b4d6-4db9-aa40-1cd32eda9845}
CLSIA|{1cd49dc9-fd88-41fa-b892-47e037267d45}
CLSIA|{201d3da8-b495-4a3b-bee8-6d8ddccc5762}
CLSIA|{26d73573-f1b3-48c9-a989-e6
ce071957a1}
CLSIA|{31ddc1fd-cea3-4837-a6dc-87e67015adc9}
CLSIA|{3446598e-00e4-4b5e-99a6-87ecca8324a2}
CLSIA|{3616f4b5-f6ad-4e67-966a-c218673648a0}
CLSIA|{3dad912e-d2b9-4323-b7c9-7f2c5cc0c57b}
CLSIA|{54579c3d-a58d-4623-b5b5-465552bda45b}
CLSIA|{624321f1-0581-49d8-99bd-2e952c2df31b}
CLSIA|{7504f0d5-644a-4103-9d02-95488b6cb9a1}
CLSIA|{78f584df-bbf5-4296-839c-31de60914dbc}
CLSIA|{8d8baf56-b581-4b90-a549-c4ac6b03f1bb}
CLSIA|{95460abd-946a-46ff-9f56-268718323eee}
CLSIA|{a1c392a2-b274-46db-89be-1fbd476b9c93}
CLSIA|{b2b0aedf-7cdf-4792-bb67-7654ad1e1b13}
CLSIA|{ba749bc1-143e-430d-b1da-1d2af67a3658}
CLSIA|{bfc9677b-8006-4336-9d49-2c797aefcb9e}
CLSIA|{c2481ed1-9896-4d49-ae90-69858dfde446}
CLSIA|{c6760a07-a574-4705-b113-7856315922c3}
CLSIA|{e114cd5b-17ce-4807-890e-7b1edf9f2e5e}
CLSIA|{e19ab99f-aec4-4b40-a5ca-f69d22522d77}
CLSIA|{e24e8472-89b7-479f-8ad8-bbd7206a6a02}
CLSIA|{e3943a24-2f83-4505-9ae5-f705e81b50cb}
CLSIA|{e7ae1661-ebeb-492b-ae0d-860df24174c6}
CLSIA|{ef4dcd99-d26b-44a4-ba77-cfdcc97e7291}
CLSIA|{efb23983-5803-4914-ada3-c0ea2cfbdc37}
CLSIA|{fa605711-8e72-46b2-ae49-bed11b2e729d}
CLSIA|{fa83e942-b796-46de-9155-1632ecc5473b}
DIREC|%ProgramFiles%\Instant Access\
AUTST|dubiloa
AUTST|Instant Access
AUTST|MovieNetworks Instant Access
FILEN|%ALLUSERSPROFILE%\Desktop\NoCreditCard.lnk
FILEN|%userprofile%\Desktop\Instant Access.lnk
FILEN|%USERPROFILE%\Start Menu\Instant Access.lnk
FILEN|%USERPROFILE%\Start Menu\NoCreditCard.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Instant Access.lnk
FILEN|egdaccess_1059.cab
FILEN|egdaccess_1059.dll
FILEN|egdaccess_1063.dll
FILEN|egdaccess_1063_xp.cab
FILEN|egdaccess_1064.dll
FILEN|egdaccess_1064_xp.cab
FILEN|egdaccess_1065.dll
FILEN|egdaccess_1065_aspiv4_xp.cab
FILEN|egdaccess_1065_xp.cab
FILEN|egdaccess_1066.dll
FILEN|egdaccess_1066_aspiv4.cab
FILEN|egdaccess_1066_xp.cab
FILEN|egdaccess_1067_aspiv4_xp.cab
FILEN|egdaccess_1068_aspiv4.cab
FILEN|egdaccess_1070_aspiv4_xp.cab
FILEN|egdaccess_1071.dll
FILEN|egdaccess_1071_aspiv4_xp.cab
FILEN|egdaccess_1071_xp.cab
FILEN|egdaccess_1072.dll
FILEN|egdaccess_1072_aspiv4_xp.cab
FILEN|egdaccess_1072_xp.cab
FILEN|egdaccess_1073.dll
FILEN|egdaccess_1073_aspiv4_xp.cab
FILEN|egdaccess_1073_xp.cab
FILEN|egdaccess_1074.dll
FILEN|egdaccess_1074_xp.cab
FILEN|egdaccess_aspiv4_1065.dll
FILEN|egdaccess_aspiv4_1066.dll
FILEN|egdaccess_aspiv4_1067.dll
FILEN|egdaccess_aspiv4_1068.dll
FILEN|egdaccess_aspiv4_1070.dll
FILEN|egdaccess_aspiv4_1071.dll
FILEN|egdaccess_aspiv4_1072.dll
FILEN|egdaccess_aspiv4_1073.dll
NEWPR|938|Interfun
PRCAT|8
CLSIA|{15c3c7a4-9676-11d3-9799-0060087190b9}
NEWPR|470|IpBill.Dialer
PRCAT|8
CLSID|{19e91d82-7ad7-419f-866a-58c122db1459}
CLSID|{266f948a-3dee-4270-8f55-e79accd569fa}
CLSID|{90a52f00-64ac-4dc6-9d7d-4516670275d0}
CLSIA|{9e1089bc-1ae8-4685-8d77-6721e5c318a8}
CLSIA|{ad7fafb0-16d6-40c3-af27-585d6e6453fd}
CLSIA|{c68ae9c0-0909-4ddc-b661-c1afb9f5ae50}
CLSID|{f5f779a9-24e5-4bcd-9ae5-6313d4b5ac24}
REGKE|HKEY_CLASSES_ROOT\comload.loader2 loader2 Class
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/comload.dll
CLASS|Comload.loader
CLASS|comload.loader2
CLASS|dctl
RKSOF|coulomb
FILEN|%WinDir%\Downloaded Program Files\comload.dll
FILEN|comload.dll
NEWPR|1229|MaConnect
PRCAT|8
CLSIA|{02c20140-76f8-4763-83d5-b660107b7a90}
CLASS|MaConnect.Loader
NEWPR|2754|MadameSalope
PRCAT|8
FILEN|%USERPROFILE%\Desktop\MadameSalope.lnk
FILEN|%USERPROFILE%\Desktop\Uninstall MadameSalope.lnk
NEWPR|2490|MarcadorCOM
PRCAT|8
CLSIA|{03fbb191-fb50-4154-91d7-587d5e3c3c9a}
CLSID|{e21f253b-db1f-451b-b1f2-8b5aa5a760fd}
CLSID|{e5b6dc84-fa86-4d2e-9fc7-4582b4770f3b}
CLASS|MarcadorCOM.Marcador
NEWPR|812|Masta Cash Dialer
PRCAT|8
CLSID|{92abacfe-ef6e-42c7-a824-d50a914b5b70}
CLASS|Loader.LoaderX
NEWPR|523|MasterDialer
PRCAT|8
CLSIA|{12e5e9d9-4366-45d9-ba41-d0bcd55ad8cf}
CLSIA|{16a7470e-229c-45f9-ae05-a87034fd14cf}
CLSIA|{2f0d1da3-f3e4-4c67-bb5c-5afd70c1a4a5}
CLSIA|{5c24626a-cc0d-49d6-8454-aaa5b97d4410}
CLSIA|{788a7678-38d7-4eec-9d20-67a86d21a7fd}
CLSIA|{b663a561-7424-4958-af76-853e80b4e1c6}
CLSIA|{d62b5127-8d03-4175-ba71-e0041595da4b}
CLSIA|{e9c87343-0e63-4aca-9b76-b155333ee67a}
NEWPR|489|MoneyTree
PRCAT|8
CLSIA|{11b6f65d-7b8d-43cb-9aae-17234a1db33a}
CLSIA|{405fd721-04ef-4ef2-ab96-fb31d32d4643}
CLSIA|{563e5df0-2c1c-4513-bbf5-d380536bb8fc}
CLSIA|{8f4e5661-f99e-4b3e-8d85-0ea71c0748e4}
CLSIA|{96b01a48-1317-4a87-91f7-10116f755705}
CLSIA|{9f2c17ac-9aa4-4c3a-82c7-ea7bcf00f03d}
CLSIA|{a0f0d762-d1de-43af-b70e-d87864743eb3}
CLSIA|{bf279130-3f58-4e26-8043-cd5688a4d4c9}
CLSIA|{c3fda8ce-9414-4e33-ac6b-4922922259a5}
CLSIA|{c89bb48c-15d9-4f4f-803e-95d90f62be62}
CLSIA|{ca7ccb52-6922-47e5-b784-3a3f82c51863}
CLSIA|{cc87b8b6-5947-46fa-9734-68196fcf9632}
CLSIA|{da9a0b1e-9b7b-11d3-b8a4-00c04f79641c}
CLSIA|{e8edb60c-951e-4130-93dc-faf1ad25f8e7}
CLSIA|{f332d106-2ef3-45c4-baf2-0f739d76b26a}
CLSIA|{f7f808f0-6f7d-442c-93e3-4a4827c2e4c8}
CLSIA|{fc87a650-207d-4392-a6a1-82adbc56fa64}
REGKE|HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/unidist.ocx
AUTST|dyfuca
AUTST|wjarafyb
CLASS|multidist.multidistctrl
CLASS|UNIDIST.UniDistCtrl
RKSOF|FCI
UINST|Hardcore
FILEN|muldist.ocx
FILEN|nem210.dll
FILEN|nem212.dll
FILEN|nem213.dll
FILEN|nem214.dll
FILEN|nem215.dll
FILEN|nem216.dll
FILEN|nem217.dll
FILEN|nem218.dll
FILEN|nsupd9x.cab
FILEN|nsupdate.dll
FILEN|unidist.ocx
FILEN|view_sex_now.exe
FILEN|wsem210.dll
FILEN|wsem213.dll
FILEN|wsem214.dll
FILEN|wsem215.dll
FILEN|wsem216.dll
FILEN|wsem218.dll
FILEN|wsem301.dll
FILEN|wsem302.dll
NEWPR|1817|Montil
PRCAT|8
CLSIA|{a41c6220-6f42-4646-b119-fbe6f4d38e3c}
CLSIA|{d1b80ebf-1a26-4fec-b0b9-dcb934c6507e}
CLASS|AccesMembre.Loader
NEWPR|1414|Movieplace
PRCAT|8
DIREC|%programfiles%\MoviePlace
AUTST|MoviePlace
NEWPR|1794|MSConnect Dialer
PRCAT|8
CLSIA|{8b22270a-71d9-4ab9-b11a-2ea1e5292f42}
NEWPR|409|Net900
PRCAT|8
FILEN|net900.exe
NEWPR|2515|NetVenda
PRCAT|8
NEWPR|2261|NetVision
PRCAT|8
CLSIA|{db893839-10f0-4af9-92fa-b23528f530af}
DIREC|%USERPROFILE%\Start Menu\Programs\FASTTRACK\
AUTST|FASTTRACKNETVISION
RKSOF|FASTTRACK
RKSOF|NETVISION
FILEN|%USERPROFILE%\Desktop\Adulti.lnk
FILEN|%USERPROFILE%\Desktop\NETVISION.lnk
FILEN|%USERPROFILE%\Desktop\Sfondi.lnk
NEWPR|2246|New Dial
PRCAT|8
NEWPR|1297|NoCreditCard Sex Dialer
PRCAT|8
NEWPR|2457|Nunci
PRCAT|8
CLSID|{da002853-42d9-4a47-a236-896d32bb7ec7}
CLSID|{ffb51760-344e-4ffb-bfff-4b18c7ac1d63}
CLSIA|{ffff0003-0001-101a-a3c9-08002b2f49fb}
DIREC|%windir%\system32\Foox
DIREC|%windir%\system32\Goox
DIREC|%windir%\system32\Winteg
DIREC|%windir%\system32\Wintx
DIREC|%WINDIR%\system32\Winx\
AUTST|Connector
AUTST|Connectors
AUTST|Winsystem
AUTST|Winsystems
RKSOF|Freeware\{DA002853-42D9-4A47-A236-896D32BB7EC7}
RKSOF|Freeware\{FFB51760-344E-4FFB-BFFF-4B18C7AC1D63}
UINST|{204131AB-C727-4CF2-8230-F47D6B1FFF70}
UINST|{30083491-2978-45D6-8BD4-DBBEB4A1AB59}
UINST|{54F7FD6E-E782-4F9F-8FF0-677090048729}
UINST|{766AF492-15F9-4C69-B73A-3D204B4C331B}
UINST|{8700A5F0-4867-41C8-AD94-7C15C0E03F8D}
FILEN|%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Night Club - Foto Annunci Video - VM18.lnk
FILEN|%USERPROFILE%\Desktop\FOTO E VIDEO DI RAGAZZE BELLISSIME.lnk
FILEN|%USERPROFILE%\Desktop\FOTO VIDEO CAM e tanto altro.?lnk
FILEN|%USERPROFILE%\Desktop\LOGHI SUONERIE E TANTO ALTRO .?lnk
FILEN|%USERPROFILE%\Desktop\Night Club - Foto Annunci Video - VM18.lnk
FILEN|%USERPROFILE%\Desktop\VIDEOCHAT GIRLS.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Night Club - Foto Annunci Video - VM18.lnk
NEWPR|1291|One2Bill
PRCAT|8
CLSIA|{00000000-6666-0704-0b53-2c8830e9faec}
CLSIA|{00000000-7777-0704-0b53-2c8830e9faec}
NEWPR|524|Online-Dialer
PRCAT|8
CLSID|{8512b008-b0aa-451f-a744-a289fd8ffde6}
CLSID|{abc7630f-71ce-4a96-9aa6-0469457b9ba3}
CLASS|Ole32ws.Moniker32
FILEN|maconnect.cab
FILEN|maconnect.dll
FILEN|od-dflt0001.exe
FILEN|od-stnd191.exe
FILEN|ole32ws.dll
NEWPR|1974|Orgasm dialer
PRCAT|8
FILEN|%systemroot%\Orgasm.exe
FILEN|%userprofile%\Desktop\Orgasm.lnk
FILEN|%userprofile%\Start Menu\Orgasm.lnk
FILEN|30500105.exe
NEWPR|789|ParisVoyeur
PRCAT|8
CLSIA|{869518c3-fba5-4d75-8a14-7047437e9498}
CLSIA|{90d610e8-f6d0-4ad4-93ce-178a46f8c412}
CLSIA|{b4e0f9cb-bc06-4a33-bbb3-f75f16b6ff5e}
DIREC|%ProgramFiles%\Montorgueil\
DIREC|%WINDIR%\Temp\MT\
RKSOF|Montorgueil
FILEN|parisvoyeur.exe
NEWPR|2592|PersonalMoneyTree
PRCAT|8
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\PMT
DIREC|%ProgramFiles%\Personal Money Tree\
DIREC|%userprofile%\Start Menu\Programs\Personal Money Tree\
UINST|Personal Money Tree
NEWPR|579|PluginAccess
PRCAT|8
CLSIA|{a1dc3241-b122-195f-b21a-000000000000}
CLSIA|{e21ae2d7-972c-4d23-bee7-a902122841e6}
FILEN|browser_plugin.cab
FILEN|browser_plugin.exe
NEWPR|799|Porn385
PRCAT|8
NEWPR|1133|Porndialer.a
PRCAT|8
CLSID|{251347ac-229a-4df4-838c-23966e119ce3}
CLSIA|{5f426a93-0821-47d2-a126-5a48a874b289}
CLSID|{9007d402-bf5c-410c-b958-9994c88d943b}
CLASS|PDialerWeb.DialerWeb
NEWPR|501|Proclaim Dialers
PRCAT|8
CLSIA|{d53b810f-6219-11d4-95b6-00
40950375e7}
FILEN|hotsurprise_be.exe
FILEN|ukvideo2.exe
NEWPR|2451|Progetto
PRCAT|8
CLSIA|{0d62a517-e7c6-4e1f-a577-07d4ac549a48}
CLSID|{391f0ac2-2cfc-4d56-a0e5-c7beb14f26e6}
CLSID|{62753dcb-b56b-46c1-831c-93387ec8135a}
CLSIA|{a1426ac5-8ce5-4a00-b71e-011d35709ac6}
CLSIA|{b7e76c25-791f-432e-bdb7-748d01a93fc2}
CLASS|Progetto1.int_ver32
CLASS|Progetto1.int_ver34
CLASS|VacPro.int_ver30
NEWPR|3509|Qdialer
PRCAT|8
NEWPR|2274|QucktIme.dialer
PRCAT|8
AUTST|bodr.exe
NEWPR|2471|RASDial-E
PRCAT|8
CLSIA|{fbff6f10-abcd-9544-832f-a1f75a0501ae}
NEWPR|1789|SCData Dialer
PRCAT|8
CLSIA|{3ecf916f-a5de-4dd4-a142-b35a29dc2edb}
CLSIA|{6ed16eff-3b18-11d6-9139-00e02964e8e3}
NEWPR|2804|Scom Dialer
PRCAT|8
DIREC|%ProgramFiles%\scom
AUTST|Gay_Sexy
RKSOF|SCom
UINST|Gay_Sexy
FILEN|%USERPROFILE%\Desktop\Gay_Sexy.lnk
FILEN|%USERPROFILE%\Start Menu\Gay_Sexy.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Gay_Sexy.lnk
NEWPR|855|SexFiles
PRCAT|8
NEWPR|2432|Sexnow
PRCAT|8
AUTST|Sexnow
FILEN|%USERProfile%\Desktop\Sexnow.lnk
FILEN|%USERPROFILE%\Start Menu\Sexnow.lnk
NEWPR|1796|SexoBFAX Dialer
PRCAT|8
CLSID|{8f575708-0000-0000-0000-000000000000}
NEWPR|1795|SexoDial
PRCAT|8
CLSIA|{8e65b894-c2e9-11d5-bcd3-00e018987501}
CLSIA|{8e65b894-c2e9-11d5-bcd3-00e018987519}
NEWPR|2419|SexyBills
PRCAT|8
NEWPR|1785|SinCity
PRCAT|8
CLSIA|{4e15d681-1d20-11d4-8b72-000021da1956}
NEWPR|2552|SkyMaster
PRCAT|8
IEZON|archiviosex.net
NEWPR|1809|SmsDialer
PRCAT|8
CLSIA|{bd11a280-2e73-11cf-b6cf-00aa00a74dae}
FILEN|%USERPROFILE%\Desktop\Kontakt Annonser.lnk
FILEN|%USERPROFILE%\Desktop\Sexleksaker.lnk
FILEN|%USERPROFILE%\Desktop\SMS KUL.lnk
NEWPR|1311|Softtec Dialer
PRCAT|8
CLSIA|{5df6fb84-749d-4aae-ae37-708de09b0588}
NEWPR|2610|SPlanet
PRCAT|8
CLSIA|{00000000-0023-0000-5400-320020040070}
NEWPR|414|StarDialer
PRCAT|8
CLSID|{c34827ea-8777-4917-927c-8f8fae1a3815}
CLSID|{d037f883-92c3-4f89-a302-c01127cf3c72}
CLSIA|{e0b795b4-fd95-4abd-a375-27962efce8cf}
CLSID|{f0bc061f-daf9-4533-8011-53bcb4c10307}
CLSID|{f1cc694e-9e9d-4913-ac41-2970aeef2bf0}
CLASS|InstallationsAssistent
RKSOF|MainPean Highspeed
FILEN|britney spears nackt.exe
FILEN|hzs-10030.exe
FILEN|starinstall.ocx
NEWPR|455|StripPlayer
PRCAT|8
CLSID|{357aa41a-b7a8-4632-a27d-5b980b25cf43}
CLSID|{bc23f736-c5be-47fb-b459-1757933e5df3}
CLSIA|{e3f7205f-2ae0-4bf0-816b-2d24a5f20ec7}
FILEN|activestripsetup.cab
FILEN|activestripsetup.dll
FILEN|stripsetup.exe
NEWPR|1949|Switchdialer
PRCAT|8
CLSIA|{5cbf8c22-e9a6-11d7-90fe-000ae4012db4}
DIREC|%ProgramFiles%\Make125\
AUTST|sVideo2
RKSOF|Make125
RKSOF|SwitchDialer
UINST|Switch
NEWPR|644|SystemVXD Dialer
PRCAT|8
FILEN|systemvxd.exe
NEWPR|1279|Sysupd
PRCAT|8
AUTST|JavaUpdate0.07
AUTST|SysUpd
NEWPR|2574|Tele Team Work Dialer
PRCAT|8
NEWPR|2482|Telemedia
PRCAT|8
CLSID|{855fb119-4791-423b-bc32-ba7e9f037bb1}
CLSID|{c1c0b1a9-fd3a-4f0b-b825-397d26f01e36}
REGKE|HKEY_CLASSES_ROOT\DIALERX.DialerXCtrl.1
NEWPR|580|TIBS
PRCAT|8
CLSIA|{0191abf4-9421-435e-9ffd-cd827a2a82d8}
CLSID|{0f9561d0-03b2-44a3-89a6-e95e417cba25}
CLSIA|{10a1b95d-5e35-4935-8bc3-d43e81e8105e}
CLSIA|{1e89f686-b78d-4c85-9efc-3474516e3fe2}
CLSID|{38d4d5d0-423e-4220-b6f9-30918c2ae4a4}
CLSID|{5ff31463-6856-4604-bee9-d84c92f60ba4}
CLSIA|{a51dedcd-20f7-11d4-98a5-00c0ca130748}
CLSIA|{b73bc7c7-858b-49fa-bbdb-74dd77d1d9f3}
CLSIA|{c1c2ac28-5e4b-4228-b7a0-05e986ffce14}
CLSID|{d88da98d-48ba-4116-96ab-77c38eae487f}
DIREC|%PROGRAMFILES%\WEBSITEVIEWER\
CLASS|atlbrcon.atlbrcon
CLASS|LoaderCon.LoaderCon
CLASS|TIBSLoaderAXDLL.TIBSLoader
RKSOF|dialer\Nude Celebrities ! \
RKSOF|TBS
RKSOF|WebSiteViewer
FILEN|%USERProfile%\Desktop\sex.lnk
FILEN|%USERProfile%\Start Menu\sex.lnk
FILEN|clbmn2.exe
FILEN|tibsloader.exe
FILEN|tl4000.dll
NEWPR|932|ToneLoc 1.1
PRCAT|8
NEWPR|2781|Trojan.Win32.Dialer.ow
PRCAT|8
NEWPR|410|TSCash
PRCAT|8
CLSIA|{13258718-b804-4092-8496-55f80aedbf1f}
CLSIA|{52290b25-d07a-43b5-84d8-493116d50fa0}
CLSIA|{de726bc4-5f2f-4984-b28b-3d6d76724f64}
FILEN|adult.exe
FILEN|cammaus.exe
FILEN|deutsche-peepshow.exe
FILEN|erotik-hotel.exe
FILEN|funland.exe
FILEN|lustmaus.exe
FILEN|megabusen.exe
FILEN|nutte.exe
FILEN|sabine.exe
FILEN|sabine2.exe
FILEN|sexstop.exe
FILEN|spanner.exe
FILEN|stchat.exe
FILEN|telefun.exe
FILEN|tscash.exe
FILEN|tscash3nos.cab
FILEN|ueber40de.exe
FILEN|xxxlivesex.exe
NEWPR|2315|Ulubione
PRCAT|8
AUTST|Ulubione
NEWPR|403|Unknown Dialers
PRCAT|8
CLSIA|{00000012-890e-4aac-afd9-kjt4964a34df}
CLSIA|{12345678-baba-caca-dada-babacacadada}
CLSIA|{1261803f-da51-4dfd-b1b6-8e26fe3d8399}
CLSIA|{13f90341-ad79-4a9f-9b57-0234675670d6}
CLSIA|{15589fa1-c456-11ce-bf01-00aa0055595a}
CLSIA|{1d4bd875-c3d8-4476-a066-3b16d2cb1ea5}
CLSIA|{1e1b2879-88ff-11d2-8d96-d7acac97972f}
CLSIA|{214868a8-f71b-473e-8ecf-6ee1de6b91d8}
CLSID|{21de6877-97c0-4fc7-9c16-666b996db4a2}
CLSIA|{28383874-c021-41be-85bd-2bba0ed4cd20}
CLSIA|{2e77e33f-671e-4334-abaa-0c2e2be654f1}
CLSIA|{38572dee-c460-481f-aa55-6289e5079ed9}
CLSIA|{3f5a62e2-51f2-11d3-a075-cc7364cae42a}
CLSIA|{41770406-8d8b-4e77-81bd-459f191f4347}
CLSIA|{459729ac-727d-4d97-b18a-72ee224efec0}
CLSIA|{459c8f4c-7b71-48e2-af72-2bb79053a5f4}
CLSIA|{50a28604-52f2-11d6-8f0f-5254ab11d5c2}
CLSIA|{75d1f3b2-2a21-11d7-97b9-0010dc2a6243}
CLSIA|{8403cb53-12b3-4537-9dec-4f12f70a883d}
CLSIA|{841a9192-5690-11d4-a258-0040954a01be}
CLSIA|{8699d723-6dc6-47d3-b55c-489ba006b917}
CLSIA|{8702d9e1-890b-4bf2-a233-fa44e582b2de}
CLSIA|{8886a618-b60a-4863-bd8b-42a24b14fc90}
CLSIA|{90803b38-6937-474c-8f80-ca1e2e8ea4ca}
CLSIA|{978a4db6-d22a-4d55-b350-dab71097bf69}
CLSIA|{a5e3b21e-ccbb-450e-9d0c-eef06076b856}
CLSIA|{b09b1d8b-88d6-4c91-bb62-378625e8c73e}
CLSIA|{b4a96063-9392-472b-8ea7-effedf873ace}
CLSIA|{b67e0278-cd82-4cca-ad9d-c1fbf538774a}
CLSIA|{bec21260-d115-4b49-99cb-f304032ee5ae}
CLSID|{c7abf7ae-67a7-495c-88e1-3d1b295e25f7}
CLSIA|{d6bd21b2-32fd-4a56-ae46-fba65eabb3a7}
CLSIA|{d9545080-34ff-4538-9419-cbe403f4885b}
CLSIA|{e2892c3d-8273-44a0-9ae7-a8d25dab81b0}
CLSIA|{efb22865-f3bc-4309-adfa-c8e078a7f762}
CLSIA|{f08555b1-9cc3-11d2-aa8e-000000000000}
CLSIA|{f1bc7ea3-a097-4c4e-9858-ab0da0f516ec}
CLSIA|{f32c4ef7-329b-4ffd-a71d-88ab39dc0849}
CLSIA|{fcaddc14-bd46-408a-9842-111111111111}
CLSIA|{fcaddc14-bd46-408a-9842-cdb57890086b}
DIREC|%userprofile%\Application Data\WinDS
DIREC|%userprofile%\Application Data\WinMS
UINST|ANIME AG
UINST|Banditos
UINST|Basteln
UINST|Download-Central
UINST|Filesharing
UINST|Firstrouting
UINST|Geburtstags- und Hochzeitsportal
UINST|Gedichte
UINST|Grusskarten Experte
UINST|Hardcore Area
UINST|Hausaufgaben
UINST|Haustiere
UINST|Jokeserver
UINST|Kazaa
UINST|Krankheiten
UINST|Krimi
UINST|Landkarte
UINST|Maerchen.ag
UINST|Malvorlagen
UINST|MobileWorld
UINST|Modeberater
UINST|Mucke.tv
UINST|Musiclab
UINST|NGFGedichte
UINST|P2P
UINST|P2P - Das Filesharingportal
UINST|Pflanzen
UINST|Piratos
UINST|Priggle
UINST|Radiofox
UINST|Routenplaner
UINST|Scoubidou
UINST|Selbst Befriedigen
UINST|Sendman
UINST|SPIELESERVER
UINST|Sportlabs
UINST|Starhacker
UINST|Suchmaschinenwelt
UINST|Tanga.AG
UINST|Tattoo
UINST|Tierheime
UINST|TOP-HUMOR
UINST|Translator
UINST|Tuxos.de
UINST|Vitalinet.de
UINST|Vorlagen
UINST|Vornamen
FILEN|%userprofile%\Desktop\ANIME AG.lnk
FILEN|%userprofile%\Desktop\Banditos.lnk
FILEN|%userprofile%\Desktop\Basteln.lnk
FILEN|%userprofile%\Desktop\Download-Central.lnk
FILEN|%userprofile%\Desktop\Filesharing.lnk
FILEN|%userprofile%\Desktop\Firstrouting.lnk
FILEN|%userprofile%\Desktop\Gamer.AG.lnk
FILEN|%userprofile%\Desktop\Geburtstags- und Hochzeitsportal.lnk
FILEN|%userprofile%\Desktop\Gedichte.lnk
FILEN|%userprofile%\Desktop\Grusskarten Experte.lnk
FILEN|%userprofile%\Desktop\Hardcore Area.lnk
FILEN|%userprofile%\Desktop\Haustiere.lnk
FILEN|%userprofile%\Desktop\Jokeserver.lnk
FILEN|%userprofile%\Desktop\Krankheiten.lnk
FILEN|%userprofile%\Desktop\Krimi.lnk
FILEN|%userprofile%\Desktop\Landkarte.lnk
FILEN|%userprofile%\Desktop\Maerchen.ag.lnk
FILEN|%userprofile%\Desktop\Malvorlagen.lnk
FILEN|%userprofile%\Desktop\MobileWorld.lnk
FILEN|%userprofile%\Desktop\Modeberater.lnk
FILEN|%userprofile%\Desktop\Mucke.tv.lnk
FILEN|%userprofile%\Desktop\Musiclab.lnk
FILEN|%userprofile%\Desktop\NGFGedichte.lnk
FILEN|%userprofile%\Desktop\P2P - Das Filesharingportal.lnk
FILEN|%userprofile%\Desktop\P2P-Filesharing.lnk
FILEN|%userprofile%\Desktop\P2P.lnk
FILEN|%userprofile%\Desktop\Pflanzen.lnk
FILEN|%userprofile%\Desktop\Piratos.lnk
FILEN|%userprofile%\Desktop\Priggle.lnk
FILEN|%userprofile%\Desktop\Radiofox.lnk
FILEN|%userprofile%\Desktop\Routenplaner.lnk
FILEN|%userprofile%\Desktop\Scoubidou.lnk
FILEN|%userprofile%\Desktop\Selbst Befriedigen.lnk
FILEN|%userprofile%\Desktop\Sendman.lnk
FILEN|%userprofile%\Desktop\SPIELESERVER.lnk
FILEN|%userprofile%\Desktop\Sportlabs.lnk
FILEN|%userprofile%\Desktop\Starhacker.lnk
FILEN|%userprofile%\Desktop\Suchmaschinenwelt.lnk
FILEN|%userprofile%\Desktop\Tanga.AG.lnk
FILEN|%userprofile%\Desktop\Tattoo.lnk
FILEN|%userprofile%\Desktop\Tierheime.lnk
FILEN|%userprofile%\Desktop\TOP-HUMOR.lnk
FILEN|%userprofile%\Desktop\Translator.lnk
FILEN|%userprofile%\Desktop\Tuxos.de.lnk
FILEN|%userprofile%\Desktop\Vitalin
et.de.lnk
FILEN|%userprofile%\Desktop\Vorlagen.lnk
FILEN|%userprofile%\Desktop\Vornamen.lnk
FILEN|%userprofile%\Start Menu\Programs\ANIME AG.lnk
FILEN|%userprofile%\Start Menu\Programs\Banditos.lnk
FILEN|%userprofile%\Start Menu\Programs\Basteln.lnk
FILEN|%userprofile%\Start Menu\Programs\Download-Central.lnk
FILEN|%userprofile%\Start Menu\Programs\Filesharing.lnk
FILEN|%userprofile%\Start Menu\Programs\Firstrouting.lnk
FILEN|%userprofile%\Start Menu\Programs\Gamer.AG.lnk
FILEN|%userprofile%\Start Menu\Programs\Geburtstags- und Hochzeitsportal.lnk
FILEN|%userprofile%\Start Menu\Programs\Gedichte.lnk
FILEN|%userprofile%\Start Menu\Programs\Grusskarten Experte.lnk
FILEN|%userprofile%\Start Menu\Programs\Hardcore Area.lnk
FILEN|%userprofile%\Start Menu\Programs\Hausaufgaben.lnk
FILEN|%userprofile%\Start Menu\Programs\Haustiere.lnk
FILEN|%userprofile%\Start Menu\Programs\Jokeserver.lnk
FILEN|%userprofile%\Start Menu\Programs\Kazaa.lnk
FILEN|%userprofile%\Start Menu\Programs\Krankheiten.lnk
FILEN|%userprofile%\Start Menu\Programs\Krimi.lnk
FILEN|%userprofile%\Start Menu\Programs\Landkarte.lnk
FILEN|%userprofile%\Start Menu\Programs\Maerchen.ag.lnk
FILEN|%userprofile%\Start Menu\Programs\Malvorlagen.lnk
FILEN|%userprofile%\Start Menu\Programs\MobileWorld.lnk
FILEN|%userprofile%\Start Menu\Programs\Modeberater.lnk
FILEN|%userprofile%\Start Menu\Programs\Mucke.tv.lnk
FILEN|%userprofile%\Start Menu\Programs\Musiclab.lnk
FILEN|%userprofile%\Start Menu\Programs\NGFGedichte.lnk
FILEN|%userprofile%\Start Menu\Programs\P2P - Das Filesharingportal.lnk
FILEN|%userprofile%\Start Menu\Programs\P2P-Filesharing.lnk
FILEN|%userprofile%\Start Menu\Programs\P2P.lnk
FILEN|%userprofile%\Start Menu\Programs\Pflanzen.lnk
FILEN|%userprofile%\Start Menu\Programs\Piratos.lnk
FILEN|%userprofile%\Start Menu\Programs\Priggle.lnk
FILEN|%userprofile%\Start Menu\Programs\Radiofox.lnk
FILEN|%userprofile%\Start Menu\Programs\Routenplaner.lnk
FILEN|%userprofile%\Start Menu\Programs\Scoubidou.lnk
FILEN|%userprofile%\Start Menu\Programs\Selbst Befriedigen.lnk
FILEN|%userprofile%\Start Menu\Programs\Sendman.lnk
FILEN|%userprofile%\Start Menu\Programs\SPIELESERVER.lnk
FILEN|%userprofile%\Start Menu\Programs\Sportlabs.lnk
FILEN|%userprofile%\Start Menu\Programs\Starhacker.lnk
FILEN|%userprofile%\Start Menu\Programs\Suchmaschinenwelt.lnk
FILEN|%userprofile%\Start Menu\Programs\Tanga.AG.lnk
FILEN|%userprofile%\Start Menu\Programs\Tattoo.lnk
FILEN|%userprofile%\Start Menu\Programs\Tierheime.lnk
FILEN|%userprofile%\Start Menu\Programs\TOP-HUMOR.lnk
FILEN|%userprofile%\Start Menu\Programs\Translator.lnk
FILEN|%userprofile%\Start Menu\Programs\Tuxos.de.lnk
FILEN|%userprofile%\Start Menu\Programs\Vitalinet.de.lnk
FILEN|%userprofile%\Start Menu\Programs\Vorlagen.lnk
FILEN|%userprofile%\Start Menu\Programs\Vornamen.lnk
FILEN|23aw0001.exe
FILEN|arr.exe
FILEN|belgium_sex-uninstall.exe
FILEN|bho.0.1.0.128.dll
FILEN|bho.0.1.0.135.dll
FILEN|crush.exe
FILEN|datemakerintl.exe
FILEN|direktsex.exe
FILEN|freesexx.exe
FILEN|go in.exe
FILEN|handy-paradies.exe
FILEN|hardcoreteens.exe
FILEN|hotsex.exe
FILEN|hotsexvideos.exe
FILEN|hot_canada.exe
FILEN|lolitasex.exe
FILEN|od-stnd24.exe
FILEN|piratos.exe
FILEN|pissing.avi.exe
FILEN|sexy-uninstall.exe
FILEN|sexy_belgium-uninstall.exe
FILEN|syswebtelecomint.dll
NEWPR|2414|VideoDialer
PRCAT|8
DIREC|%ProgramFiles%\hbt\
AUTST|Blondes
AUTST|Hot_Tarts_mc
CLASS|.vmxy
CLASS|vmxy File
RKSOF|hbt
UINST|Hot_Tarts_mc
FILEN|%USERPROFILE%\Desktop\Blondes.lnk
FILEN|%USERPROFILE%\Desktop\Hot_Tarts_mc.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Blondes.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Hot_Tarts_mc.lnk
NEWPR|2506|VividGal
PRCAT|8
NEWPR|411|VLoading
PRCAT|8
CLSIA|{00000000-8633-1405-0b53-2c8830e9faec}
CLSIA|{11bf0e2b-4229-4adc-9c11-1c6968731018}
CLSIA|{67355a47-1544-4905-b698-4d7e5b62ec32}
CLSIA|{91df007c-2f7f-4731-be1f-38c1c13ceb8b}
CLSIA|{ab1e62eb-3de3-428f-a417-64ab3c9b6cf0}
CLSIA|{e44151c8-0c6c-4a7d-b677-4fcc9552e957}
CLASS|econnect.econn
CLASS|VLoading.Download
FILEN|econnect.dll
FILEN|suninfoconnect.dll
FILEN|vloading.cab
FILEN|vloading.dll
NEWPR|3534|W32.Dialer.PornAgent
PRCAT|8
NEWPR|2491|Wild-Flics
PRCAT|8
AUTST|Wild-Flics
FILEN|%USERPROFILE%\Desktop\Wild-Flics.lnk
FILEN|%USERPROFILE%\Start Menu\Wild-Flics.lnk
NEWPR|2226|Win32.Dialer
PRCAT|8
CLSIA|{3d000ecf-1fc1-2c30-c6ac-53494a04b651}
CLSIA|{430bf633-8d63-4891-e908-34d11db86ce4}
CLSIA|{46fba988-a778-6fb8-d917-0da25be4bd7a}
CLSIA|{500080d2-3ef6-4d87-1b30-3d0373d8627b}
CLSIA|{5202e9cd-423b-2813-6a29-3f6232104e67}
CLSIA|{6520eb87-fe23-7aec-0476-6a345e1028c8}
CLSIA|{66c80766-743b-1078-33b0-57926c86edb0}
CLSIA|{7baafd67-98ac-5db9-176e-10d7387c9afa}
DIREC|%WINDIR%\_DlrApps\
AUTST|\windows\syswin.exe
NEWPR|3436|win32.Dialer.gsa
PRCAT|8
NEWPR|801|WinDialer
PRCAT|8
CLSIA|{4bcf322b-9621-4e90-9678-f1424eb7584e}
NEWPR|529|Wonderland
PRCAT|8
CLSIA|{08ee9c58-d8b4-4977-8198-9c771cd8c451}
CLSIA|{0f5b6a38-b470-4446-b453-c248d8fb3a4b}
CLSIA|{6d6ddf37-b491-49d3-8733-600fa16940a0}
CLSIA|{9ddc8f6d-bc51-46cb-b185-ebf34d52a175}
CLSIA|{d06855e1-7758-430f-9e20-274d32c0472e}
CLSIA|{efcf25f1-c8f9-4c53-a03d-68d5c19225d0}
CLASS|Cab33107.Cab_33107
CLASS|WonderPlus.Wonder_Plus
CLASS|WonderWeb.Wonder_Web
FILEN|agrit.exe
FILEN|alberghi.exe
FILEN|cab33107.cab
FILEN|qualsiasi.exe
FILEN|wonderplus.cab
FILEN|wonderplus.ocx
FILEN|wonderplus05.cab
FILEN|wonderplus07.cab
FILEN|wonderplus91.cab
FILEN|wonderplus91.ocx
FILEN|xxlav003.exe
NEWPR|412|X-Diver
PRCAT|8
CLSID|{e17e606a-9836-4619-a249-f40d5d2e812a}
FILEN|xdiver.exe
NEWPR|537|XDialer
PRCAT|8
CLSIA|{1e50b82a-0d78-48b9-97ec-391b2f81ce8a}
CLSIA|{4bf9bc08-8571-4e2b-aecf-ec8c9e287c04}
CLSIA|{69a4f9ff-e915-11d5-a9f1-009099104002}
CLSIA|{8dce908e-9e35-11d3-9431-009099104002}
CLSIA|{9e7138ee-4e7b-11d5-94ef-006008a4ed7f}
CLSIA|{daca803e-b6de-11d4-80e5-0060974b8983}
CLSIA|{e28e4df0-2bca-4904-bcf9-a983e3a80a64}
FILEN|xdial.ocx
NEWPR|2496|XEng004
PRCAT|8
AUTST|DateCheck
NEWPR|2442|Xgen-A
PRCAT|8
CLSIA|{11111111-1111-1111-1111-119357210284}
REGKE|HKEY_CURRENT_USER\dialein2
NEWPR|2589|Xgratos
PRCAT|8
NEWPR|682|XLoader
PRCAT|8
CLSIA|{8c6c6922-6258-44ac-9912-53964ac55272}
CLSIA|{aaaaaaaa-cccc-cccc-dddd-100000000000}
FILEN|xgenius.cab
FILEN|xgenius.exe
FILEN|xgenius.jar
NEWPR|797|Xpehbam Dialer
PRCAT|8
CLSIA|{ad688740-5246-40c3-1111-53959999940d}
CLSIA|{ad688740-5246-40c3-af27-090006046834}
NEWPR|2446|YeakNet
PRCAT|8
DIREC|%APPDATA%\sgrunt\
DIREC|%APPDATA%\tofareraci\
AUTST|oeuai
AUTST|Olympic
IEZON|*.aflashcounter.com
IEZON|1987324.com
IEZON|adslconnection.name
IEZON|sgrunt.biz
IEZON|softlab.name
IEZON|www.1987324.com
IEZON|www.adslconnection.name
IEZON|www.sgrunt.biz
IEZON|www.softlab.name
IEZON|xxx-content.name
NEWPR|1373|Aladino Backdoor
PRCAT|10
AUTST|Regdll32
NEWPR|1372|Almaster
PRCAT|10
FILEN|almaster.exe-34cdc7f0.pf
NEWPR|1425|Alvgus
PRCAT|10
NEWPR|1374|Amanda
PRCAT|10
NEWPR|1375|Arsd Backdoor Installation
PRCAT|10
NEWPR|462|ASpam
PRCAT|10
CLSIA|{499db658-1909-420b-931a-4a8caefd232f}
CLSIA|{657b9354-bb3b-4500-a9b0-109b4fa64815}
NEWPR|2642|B-[R.A.T]-T
PRCAT|10
AUTST|afkasjhfa3254f
RKSOF|BrosTeam
NEWPR|1377|Badboy
PRCAT|10
NEWPR|1380|Birdspy Trojan
PRCAT|10
NEWPR|1381|Blackharaz Trojan
PRCAT|10
NEWPR|1384|Blador.Trojan
PRCAT|10
NEWPR|783|Boss Watcher 1.0
PRCAT|10
RKSOF|Brigsoft
NEWPR|1490|Coma
PRCAT|10
NEWPR|1524|DirectConnection
PRCAT|10
NEWPR|846|FeRAT
PRCAT|10
NEWPR|1593|Freak88
PRCAT|10
NEWPR|936|Hack'a'Tack
PRCAT|10
FILEN|backdoor.hacktack.110.exe
FILEN|backdoor.hacktack.112.exe
FILEN|backdoor.hacktack.120.b.exe
FILEN|backdoor.hacktack.exe
NEWPR|2765|HackAttack
PRCAT|10
NEWPR|905|Hacker Defender
PRCAT|10
NEWPR|2460|Hatr3d F3ind
PRCAT|10
CLASS|FlatButt.FlatButton
NEWPR|1410|Iddono
PRCAT|10
NEWPR|2455|ItADeM
PRCAT|10
NEWPR|1143|Koko Trojan
PRCAT|10
NEWPR|887|LANfiltrator
PRCAT|10
NEWPR|1599|MiniOblivion
PRCAT|10
NEWPR|2468|MsnTroyano
PRCAT|10
AUTST|wini
NEWPR|826|NetBus
PRCAT|10
NEWPR|562|Optix
PRCAT|10
AUTST|GLSetIT32
NEWPR|2704|Osiris
PRCAT|10
NEWPR|2494|Prayer
PRCAT|10
NEWPR|950|Roach
PRCAT|10
NEWPR|1024|ShowPass 1.0
PRCAT|10
NEWPR|2447|Taladrator
PRCAT|10
NEWPR|955|Timbuktu Pro
PRCAT|11
NEWPR|1255|CasinoRewards
PRCAT|15
CLSIA|{ff905e0c-cfe9-4a90-afff-c13af5d908f0}
NEWPR|1028|Ebates Moe Money Maker
PRCAT|15
CLSID|{6685509e-b47b-4f47-8e16-9a5f3a62f683}
CLSID|{7f241c00-dab6-11d5-aaa8-0001028df1bc}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Ebates.
DIREC|%programfiles%\ebatesmoemoneymaker
DIREC|%programfiles%\EbatesMoeMoneyMaker1
DIREC|%programfiles%\EbatesMoeMoneyMaker2
DIREC|%programfiles%\EbatesMoeMoneyMaker3
DIREC|%programfiles%\EbatesMoeMoneyMaker4
DIREC|%programfiles%\Ebates_MoeMoneyMaker
DIREC|%programfiles%\Web Offer
AUTST|djebmm350.exe
AUTST|ebatesmoemoneymaker
AUTST|ebatesmoemoneymaker0
AUTST|ebatessvr2.xml
AUTST|WebSavingsFromEbates0
RKSOF|Ebates
RKSOF|microsoft\internet explorer\menuext\ebates
RKSOF|Web Offer
RKSOF|Web Savings
UINST|ebatesver2.xml
UINST|ebateswebsavings0.xml
UINST|ebateswebsavingsdr0.
FILEN|%ALLUSERSPROFILE%\Start Menu\Programs\Ebates Moe Money Maker\Ebates Moe Money Maker FAQ.lnk
FILEN|disp350.exe
FILEN|eapbh.dll
FILEN|ebatesmoemoneymaker.exe
FILEN|ebatesmoemoneymaker1.exe
FILEN|ebatesmoemoneymaker[1].cab
FILEN|sepng.dll
FILEN|websavingsfromebates.exe
FILEN|websavingsfromebates0.exe
NEWPR|1144|OpinionBar
PRCAT|15
CLSID|{6607c683-ae7c-11d4-acd7-0050dac291a2}
DIREC|%ProgramFiles%\OpinionBar\
DIREC|%USERPROFILE%\Start Menu\Programs\OpinionBar
CLASS|MyIEMonitor.MyIEMonitorObject
RKSOF|UniversalOpinions\OpinionBar
NEWPR|739|Top Moxie
PRCAT|15
CLSIA|{05ce4481-8015-11d3-9811-c4da9f000000}
CLSIA|{0ab5cbcf-6984-4122-bcf7-be33bf5b1cf1}
CLSIA|{1954a4b1-9627-4cf2-a041-58aa2045cb35}
CLSIA|{22e5705c-991a-4646-9053-a9525ca7222a}
CLSIA|{330110a5-f627-4dd7-b0f1-24d09c4da870}
CLSIA|{412f2472-59bc-4ccb-a3d4-c16a7d57cdcf}
CLSIA|{7ef1788a-8c66-4a77-95d2-3341111e4acd}
CLSIA|{9522b3fb-7a2b-4646-8af6-36e7f593073c}
CLSIA|{b7b7eea4-dac2-4e87-a6e8-b583e846389a}
CLSIA|{c6b086d2-146b-47a4-a218-b82dcaf2d872}
CLSIA|{e2cf5c45-7ccc-11d4-9bd1-0080c6f60b6a}
CLSIA|{e389b374-bb5a-4a73-acf4-3ce63e4c1de9}
DIREC|%ProgramFiles%\Care2_GTU\
DIREC|%ProgramFiles%\WebSavingsfromEbates\
DIREC|%ProgramFiles%\Web_Cpr\
AUTST|Care20
AUTST|couponsandoffers
AUTST|WebCpr0
RKSOF|Update Manager
UINST|uncare200
NEWPR|804|WebRebates
PRCAT|15
CLSID|{01fc5803-8644-45d7-877b-5a3924d8ecc4}
CLSID|{03f8822f-8877-4002-8bcd-b532d53d8471}
CLSID|{0a8ce102-fa03-4612-9bee-7fe5452f4cb1}
CLSID|{3d156636-3f7e-46c9-9ac1-5e4d8202aa23}
CLSID|{4eb7bbe8-2e15-424b-9ddb-2cdb9516c2e3}
CLSIA|{7eb15626-cb8e-4174-8a72-c055b12b4310}
CLSID|{bcf96fb4-5f1b-497b-aecc-910304a55011}
CLSID|{f8fb4ea2-6c05-4de5-8cd0-625b03f48e22}
DIREC|%programfiles%\webrebates
DIREC|%programfiles%\WebRebates4\
DIREC|%programfiles%\web_rebates
DIREC|%programfiles%\Web_Rebates\
DIREC|%SystemRoot%\winskw
DIREC|%windir%\bundles
AUTST|%programfiles%\Web_Rebates\
AUTST|blubstersupport
AUTST|untopr11150
AUTST|upromiseremindu
AUTST|webrebates
AUTST|WebRebates0
AUTST|websavingsfromebates
CLASS|ImgConv.clsImgConv
RKSOF|Microsoft\Internet Explorer\MenuExt\Web Rebates.
RKSOF|Web Rebates
UINST|unebmm350
UINST|untopr1150
FILEN|disp1150.exe
FILEN|sahagent-seedcorn1002.exe
FILEN|w11150.exe
FILEN|webrebates.dll
FILEN|webrebates.exe
FILEN|webrebates0.exe
FILEN|webrebates1.exe
FILEN|webrebates2.dll
FILEN|webrebates2.exe
FILEN|webrebatesrun.exe
FILEN|webrebates_auto_installsilent.exe
NEWPR|418|Alexa Toolbar
PRCAT|16
CLSID|{04d79e9f-09a9-4aed-9fc2-6e63a3bca51e}
CLSID|{0a291298-dfb0-4b0d-b547-5a66fd709d57}
CLSID|{0b32bccd-4d64-48eb-8ec3-9ba0807d1349}
CLSID|{0bbb0424-e98e-4405-9a94-481854765c80}
CLSID|{0f3332b5-bc98-48af-9fac-05fec94ebe73}
CLSID|{11b7c44d-3bd8-42a7-aa69-a1bed9723e9c}
CLSID|{1c1f99ea-8b5d-4d08-b6a8-b1e4cb542f9e}
CLSID|{27d784d7-9217-4227-b43b-e06e4781e0cb}
CLSID|{36600c37-fac4-471e-90bb-fc7a9c979c24}
CLSID|{3ceff6cd-6f08-4e4d-bccd-ff7415288c3b}
CLSID|{3df73df8-41e2-4fc2-8cbf-4b9407433755}
CLSID|{3e60160f-0ed6-4dcc-b6b6-850cde4fd217}
CLSID|{3f41980d-b681-488e-9757-0c9744f9c3ce}
CLSID|{446edfee-3a1a-11d3-bd49-00600827885e}
CLSID|{446edfef-3a1a-11d3-bd49-00600827885e}
CLSID|{49160f0d-6be2-4f5f-bcdb-9256da3bb120}
CLSID|{4f7cc126-4cff-4db5-892d-da71a7552c99}
CLSID|{533b5798-12d1-4063-8cd0-ffe842de872d}
CLSID|{547ab549-4dd8-4ea0-b070-f6ea062148ff}
CLSID|{5641f13a-f62e-4326-a5b6-551103ba6272}
CLSID|{57405e21-4f6d-11d3-bd52-00600827885e}
CLSID|{5a9961fd-b0a6-4065-9552-ebfc199683a3}
CLSID|{5cdc7a97-f8e3-4ea6-b0a7-578ecd31de2c}
CLSID|{62e5bcee-2b5f-4866-8b19-197cfacb770c}
CLSID|{68721ce6-c7c1-4c37-ab1f-51644f20b073}
CLSID|{6912beb3-e20c-4953-8c8e-e91b12b55bfc}
CLSIA|{69a72a8a-84ed-4a75-8ce7-263dbef3e5d3}
CLSIA|{6af9bc61-3cc5-42a7-82d1-ffc2562a7289}
CLSID|{6cf4d74b-e6bd-4c8f-83d7-90d6439705b9}
CLSID|{7280333e-17d0-4246-9510-2d6170468585}
CLSID|{738cb0ed-54a7-4061-ae2e-40efd9b1eef6}
CLSID|{79a4d241-de89-11d3-ac85-00c04f2ee811}
CLSID|{7b068023-1ac9-4168-a133-9fdd9361af80}
CLSID|{7bf3a7db-a516-4e24-b40a-f60b34699e26}
CLSID|{7e22206d-52d1-11d4-acb8-00c04f2ee811}
CLSID|{7e22206e-52d1-11d4-acb8-00c04f2ee811}
CLSID|{8561ae3b-1832-471b-ac4f-da479d635b8e}
CLSID|{911a1dfe-c959-11d3-8164-00c04f30faf9}
CLSID|{9af74448-ebd1-484c-8b06-35e597c0b54c}
CLSID|{9bab764b-e4f3-4c7b-99ad-cdf636bbe3a8}
CLSID|{9d74677a-e227-40fb-9511-f7e92ea4083a}
CLSID|{a69107cc-bec8-4a34-b474-211b0f46a764}
CLSID|{a6a08cbd-6673-41b1-b997-3f83a25b45b0}
CLSID|{abf7c4d4-53ef-4c15-8951-d22f63c98e9f}
CLSID|{ac2a5e17-05ed-4e62-86e5-84779e8f0bca}
CLSID|{b3b1d367-4253-42b9-b620-31a7d7710a06}
CLSID|{b71c7d9a-da43-4e8b-bb9b-1684ac2af324}
CLSID|{b79d9232-a798-43db-9e61-281d550460e4}
CLSID|{b7b84995-8b92-46bf-94aa-fa2f3dd23b84}
CLSID|{bcf4d74b-e6bd-4c8f-83d7-90d6439705b9}
CLSID|{c42000c4-703a-4a55-b8af-5c83b24c9922}
CLSID|{c95fe080-8f5d-11d2-a20b-00aa003c157a}
CLSIA|{ca68bdcc-579c-4730-99f5-37c4e206e4f9}
CLSID|{d1f6abee-b889-11d2-8e3c-dcca155f9a71}
CLSIA|{d1f6abef-b889-11d2-8e3c-dcca155f9a71}
CLSID|{d32ea48b-025d-4ced-810b-b2d805478837}
CLSID|{dc21cede-3b81-43d7-b816-daefa7b4901f}
CLSID|{e3978204-d428-11d3-8164-00c04f30faf9}
CLSID|{ea20f195-32da-4bd6-b348-fd01fc7d3d5a}
CLSID|{eacaa5ce-99b3-470e-9629-8f9ef4c4b637}
CLSID|{eccc5b5c-fa9f-42a1-993f-c67a8161f5a0}
CLSID|{f1fabe79-25fc-46de-8c5a-2c6db9d64333}
CLSID|{f88028b4-4523-4ec4-a48e-064db9952f30}
CLSID|{fa77ad79-09cf-41fb-b171-cc856f9e737f}
CLSID|{fb1d5ef1-df31-11d3-ac86-00c04f2ee811}
DIREC|%ProgramFiles%\Alexa Toolbar\
CLASS|alxbw.bblhtml
CLASS|alxbw.bblwnd
CLASS|alxbw.browserwnd
CLASS|AlxTB.BHO
CLASS|bhoalexa.bhoalexa
CLASS|PopMenu.Menu
CLASS|Popup.PopupKiller
RKSOF|Alexa Internet
RKSOF|Alexa Toolbar
UINST|Alexa Toolbar
UINST|Alexa65
FILEN|alexainstaller.exe
NEWPR|2658|DialupRipper
PRCAT|16
NEWPR|488|MarketScore
PRCAT|16
CLSIA|{0bb33da5-94b7-401f-9c0a-eb75fc492b78}
CLSIA|{0f5e63ae-8b1a-11d3-80a4-0050da2d7351}
CLSID|{169c7855-c096-4d45-803b-6441552a7e92}
CLSIA|{22536211-e807-49cd-a24e-a903af91feb1}
CLSIA|{35b7e48b-9d81-4c6c-9578-5fd4f620d886}
CLSIA|{4bbe1e26-8ded-11d4-9635-000086522e52}
CLSIA|{b2c03e2e-2219-4ff9-810a-540aca63f8d9}
CLSID|{f88527e2-a8a7-4227-8683-05cfa4eec511}
AUTST|nscheck
AUTST|OSS
AUTST|OSSProxy
AUTST|RelevantKnowledge
CLASS|Nsconfig.nsBrowserConfig
RKSOF|netsetter
UINST|Marketscore
UINST|{8edf80b6-2926-4737-981f-5fd7ec9bf662}
UINST|{eeb86aef-4a5d-4b75-9d74-f16d438fc286}
FILEN|%systemroot%\system32\rk.bin
FILEN|csloa.dll
FILEN|mksc.exe
FILEN|nsconfig.dll
FILEN|okshook.dll
FILEN|osmim.dll
FILEN|ossproxy.exe
FILEN|rlvknlg.exe
NEWPR|607|NavExcel
PRCAT|16
CLSID|{20f36af3-3486-4bb6-8bcb-f1f8abe74d07}
CLSID|{5aa06644-bc46-4220-a460-47a6eb47c96d}
CLSID|{710bcb5b-8c6c-483e-a4f5-faf083b13184}
CLSIA|{b5ef836b-7582-4d82-9246-17f6c40ddf0f}
CLSIA|{c1e58a84-95b3-4630-b8c2-d06b77b7a0fc}
CLSID|{d80c4e21-c346-4e21-8e64-20746aa20aeb}
CLSID|{fa4de133-d3c3-4ed4-92d1-cd4dde839ab3}
DIREC|%ProgramFiles%\NavExcel Search Toolbar\
DIREC|%programfiles%\NavExcel\
CLASS|NavExcel.NavHelper
CLASS|NHelper.DLL
RKSOF|NavExcel
UINST|NavExcel Search Toolbar
UINST|NavHelper
FILEN|navinst2.ocx
FILEN|nhelper.dll
FILEN|nhupdater.exe
NEWPR|3228|HTTP Tunnel Client
PRCAT|38
DIREC|%AllUsersprofile%\Start Menu\Programs\HTTP-Tunnel
DIREC|%ProgramFiles%\HTTP-Tunnel\
FILEN|%AllUsersprofile%\Desktop\HTTP-Tunnel Client.lnk
FILEN|http-tunnelclient.exe
FILEN|httptunnelinstallerv403065.exe
NEWPR|3227|Proxy based anonymizers
PRCAT|38
NEWPR|3464|ProxyDex
PRCAT|38
NEWPR|3357|Ad Armor
PRCAT|43
DIREC|%ProgramFiles%\Ad Armor\
DIREC|%USERPROFILE%\Start Menu\Programs\Ad Armor\
AUTST|Ad Armor
AUTST|Ad Armor Monitor
AUTST|AdArmor.exe Monitor
RKSOF|Ad Armor
UINST|Ad Armor
FILEN|%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Ad Armor.lnk
FILEN|%USERPROFILE%\Desktop\AdArmor.lnk
FILEN|adarmor.dll
FILEN|adarmor.exe
FILEN|adarmorinstaller.exe
FILEN|adarmor_monitor.exe
FILEN|adarmor_updater.exe
NEWPR|3463|Ad-Purge Adware and Spyware Remover
PRCAT|43
NEWPR|3472|ADS Adware Remover
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\ADS Adware Remover\
DIREC|%programfiles%\ADS Adware Remover\
UINST|ADS Adware Remover_is1
FILEN|%userprofile%\Desktop\ADS Adware Remover.lnk
FILEN|ads adware remover.exe
FILEN|adsremover.exe
NEWPR|2643|Advanced Email Monitoring
PRCAT|43
DIREC|%Programfiles%\Advanced Email Monitoring\
DIREC|%USERPROFILE%\Start Menu\Programs\Advanced Email Monitoring\
UINST|Advanced Email Monitoring
NEWPR|3442|AdwareDeluxe
PRCAT|43
REGKE|HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\alertSpy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\alertSpy.exe
DIREC|%programfiles%\alertSpy\
DIREC|%userprofile%\Start Menu\Programs\alertSpy\
RKSOF|Mandel Enterprises
UINST|alertSpy
FILEN|%userprofile%\Desktop\alertSpy.lnk
FILEN|alertspy.exe
NEWPR|2733|AlfaCleaner
PRCAT|43
REGKE|HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\AlfaCleanerService
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\AlfaCleaner\
DIREC|%APPDATA%\AlfaCleaner\
DIREC|%Programfiles%\AlfaCleaner\
AUTST|AlfaCleaner
UINST|AlfaCleaner.co
m_is1
FILEN|%USERPROFILE%\Desktop\AlfaCleaner.lnk
SERVK|alfacleaner
SERVK|AlfaCleanerService
FILEN|alfacleaner.exe
NEWPR|3323|AntiVermins
PRCAT|43
CLSID|{01775f16-b10c-b483-63e3-afced5dcdef2}
CLSID|{118601e4-0bc8-4b98-aaec-723eba43ed33}
CLSID|{15548c74-5c8b-4911-ae88-739dd473e2ba}
CLSID|{468164cc-476e-47d5-9269-278d0db22a13}
CLSID|{478b7d17-f00a-4ab3-b802-46972cab1ae9}
CLSID|{4fcd9ab0-0765-4117-a612-db3b4fac1ee3}
CLSID|{5d89ba32-c9f8-48cc-b22a-18c808df6d83}
CLSID|{698664ff-f50e-4bdc-b9c0-c00f96a64b84}
CLSID|{823b335c-00de-4886-be7a-fbdc0f69294e}
CLSID|{89ae8b3e-3ee8-4068-8932-60ca9e6ac40b}
CLSID|{93362b42-9631-4bae-92ef-7726e5dd747d}
CLSID|{999e9507-216c-4a7a-b103-57d3ff617e49}
CLSID|{a5a2382e-6ea1-40c9-9eeb-fce758a7a3f1}
CLSID|{c20782a3-b65d-41ab-8d04-bbe3122363c2}
CLSID|{c54890b0-b9f8-4e58-9715-8c58b52a4d5d}
CLSID|{d037be5c-7e06-4d4d-8729-fd1ee7e59c89}
CLSID|{d108017b-1769-4bfb-8a4c-0e6202fdbd08}
CLSID|{decc44f4-e972-4e5c-8f5f-238295c5add5}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiVerminser.exe\
DIREC|%programfiles%\AntiVerminser\
DIREC|%USERPROFILE%\start menu\programs\AntiVerminser\
WINDO|AntiVerminser 2.1
WINDO|AntiVerminser v2.1
AUTST|AntiVerminser
RKSOF|AntiVerminser
UINST|AntiVerminser
FILEN|%APPDATA%\microsoft\internet explorer\quick launch\Antiverminser 2.1.lnk
FILEN|%USERPROFILE%\desktop\AntiVerminser.lnk
FILEN|%USERPROFILE%\start menu\AntiVerminser 2.1.lnk
FILEN|antiverminser.exe
FILEN|av_setup.exe
NEWPR|3495|AntiVirus Protector
PRCAT|43
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusProtection.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Telecom Advance\Antivirus Protection
DIREC|%programfiles%\Antivirus Protection\
DIREC|%userprofile%\Start Menu\Programs\Antivirus Protection\
AUTST|AntivirusProtection
UINST|Antivirus Protection
FILEN|%userprofile%\Desktop\Antivirus Protection.lnk
FILEN|antivirusprotection.exe
NEWPR|3493|Antivirus Solution
PRCAT|43
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusSolution.exe
DIREC|%programfiles%\Antivirus Solution\
DIREC|%userprofile%\Start Menu\Programs\Antivirus Solution\
AUTST|AntivirusSolution
RKSOF|6D Solutions International Inc.
UINST|Antivirus Solution
FILEN|%userprofile%\Desktop\Antivirus Solution.lnk
FILEN|%windir%\system32\filekiller.dll
FILEN|antivirussolution.exe
FILEN|antivirus_solution_setup_1.0.0.exe
NEWPR|2793|BraveSentry
PRCAT|43
DIREC|%programfiles%\BraveSentry\
DIREC|%userprofile%\Start Menu\Programs\BraveSentry\
WINDO|BraveSentry 2.0
AUTST|BraveSentry
RKSOF|BraveSentry
UINST|BraveSentry
FILEN|%userprofile%\Desktop\BraveSentry.lnk
FILEN|bravesentry.exe
FILEN|bravesentry0.dll
FILEN|bravesentry1.dll
FILEN|bravesentry2.dll
FILEN|bravesentry3.dll
FILEN|bravesentrysetup.exe
NEWPR|3552|ContraVirus
PRCAT|43
CLSID|{1be8c6a5-a75f-4e33-89c3-18cc58a0b952}
CLSID|{2c02e5fc-7fe3-4122-911f-829314fe9bbc}
CLSID|{32bd20fd-41fd-47fb-9bc9-28dcbd7d55d7}
CLSID|{61877300-54db-4746-ba42-03e03a2b269c}
CLSID|{63321a5c-d8fe-432c-8d2f-61c0fc264320}
CLSID|{6b677f1f-f86c-4757-bf24-7d865ef20639}
CLSID|{7c11c36c-2ae0-4489-9b09-a6129139d52d}
CLSID|{99a753c6-e429-46bd-989e-dd4a21cd059d}
CLSID|{bbbd3e11-d201-46c9-8471-091d33159287}
CLSID|{bfcbb188-18e3-1deb-59d5-bace1ce655a4}
CLSID|{d2c1986a-fbec-4472-aabf-6d42f08dbc8e}
CLSID|{dbe5bee8-f032-11db-826a-c4bb56d89593}
CLSID|{ea038ddd-0fe0-41f5-ba60-fc3660529e71}
CLSID|{f51bc478-d997-4c56-988d-79d9eeaad1ec}
CLSID|{fd4dcb8b-c33a-4e70-a351-6fab7e1071a4}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\Ad-Protect.Addin.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ad-protect.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ContraVirus.exe
DIREC|%appdata%\AdProtect NoSpam\
DIREC|%programfiles%\ContraVirus\
DIREC|%userprofile%\Start Menu\Programs\ContraVirus\
AUTST|ContraVirus
AUTST|Windows Updater Servc
CLASS|Ad-Protect.Addin
CLASS|IEControl.IEExtension
CLASS|SCToolBand.SCToolBandObj
CLASS|ToolBarNotifier.Notifier
RKSOF|ContraVirus
UINST|ContraVirus
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\ContraVirus 2.0.lnk
FILEN|%temp%\ContraVirus 2.0 Installer.exe
FILEN|%userprofile%\Desktop\ContraVirus 2.0.lnk
FILEN|%userprofile%\Start Menu\ContraVirus 2.0.lnk
FILEN|contravirus.exe
FILEN|contraviruspro.exe
FILEN|cvantispam.dll
FILEN|cv_1_setup.exe
FILEN|desktopmanager.dll
FILEN|secieaddin.dll
FILEN|startupeditor.dll
FILEN|xpuupdate.exe
NEWPR|3575|CurePCSolution
PRCAT|43
CLSID|{2687b107-2b13-410a-a850-be211b74af12}
DIREC|%allusersprofile%\Start Menu\Programs\CurePCSolution\
DIREC|%programfiles%\CurePCSolution\
UINST|{2687B107-2B13-410A-A850-BE211B74AF12}
FILEN|%allusersprofile%\Desktop\Start CurePCSolution.lnk
FILEN|%allusersprofile%\Start Menu\Programs\Startup\Start CurePCSolution.exe.lnk
FILEN|curepcsolution.exe
NEWPR|3150|Drive Cleaner
PRCAT|43
CLSID|{22024dc7-d190-44ec-9d49-aee5f244a466}
CLSIA|{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6}
CLSID|{7ec618f2-c506-4221-9f56-792b92bf762e}
CLSID|{943b96a4-9bf6-42fe-8d0b-4bca71c3632f}
CLSID|{c4c4786c-9861-46d2-bb63-ac782ab07046}
DIREC|%allusersprofile%\Start Menu\Programs\DriveCleaner 2006 Free
DIREC|%programfiles%\DriveCleaner 2006 Free
DIREC|%userprofile%\Local Settings\Temp\UDC6_0001_D19M1908
AUTST|DC6_check
AUTST|DriveCleaner 2006 Free
CLASS|UDCPChk.UDCPChk
CLASS|UDCShell
RKSOF|drivecleaner 2006 free
UINST|UDC6_is1
FILEN|%userprofile%\Desktop\DriveCleaner 2006 Free.lnk
FILEN|udc2006.exe
NEWPR|3511|Error Protector
PRCAT|43
DIREC|%allusersprofile%\Application Data\ErrorProtector Free\
DIREC|%allusersprofile%\Start Menu\ProgramsErrorProtector Unregistered Version\
DIREC|%allusersprofile%\Start Menu\Programs\SystemDoctor 2006 Unregistered Version\
DIREC|%ProgramFiles%\Common Files\ErrorProtector Free\
DIREC|%ProgramFiles%\ErrorProtector Free\
DIREC|%userprofile%\Administrator\Application Data\ErrorProtector Free\
AUTST|ErrorProtector Free
AUTST|pas_check
AUTST|Salestart
AUTST|SystemDoctor 2006 Free
AUTST|USDR6cw
RKSOF|ErrorProtector Free
RKSOF|uIconnoIgenannoIEewnooEwoMcocwhMgewne
FILEN|%userprofile%\Desktop\ErrorProtector.lnk
FILEN|%userprofile%\Desktop\WinAntiVirus Pro 2007.lnk
NEWPR|2740|ErrorSafe
PRCAT|43
CLSID|{05324ed1-05c0-4e3a-a34f-98bfc64426f5}
CLSID|{06170642-fa65-4fb6-ac79-5f235cb99bc2}
CLSID|{0ba379c6-0efd-4a28-932c-d20469052fd9}
CLSID|{0bc09fc7-473d-4f9c-b49b-f4e3e244b47a}
CLSID|{0d146b7f-fa35-465d-b716-bcbc1f9a92d3}
CLSID|{12813770-461e-4a9f-8c5b-c227a8e9fbe8}
CLSID|{1562d24e-f5bf-4bb4-af4c-bbb610b62638}
CLSID|{1640de0e-75e4-4a83-b5d1-2492bc7eba8f}
CLSID|{16deee6b-aefc-4ba6-9f32-57bbe6783a7c}
CLSID|{184b0a26-4c9c-4757-abf5-4b6af71f9a45}
CLSID|{18a41b20-e519-47a1-b545-ffc200730e9b}
CLSID|{196c80cb-20a7-4cf9-9c98-9322fb1e35fb}
CLSID|{1b197c22-561f-455f-8511-35b1a45c5c9f}
CLSID|{21c724d0-b91a-4f35-99e7-55d325f00b20}
CLSID|{250d1063-5414-4fb0-86d5-aabb7a5d7da7}
CLSID|{2a1647e8-3ec2-49fe-b632-e12d765fa0cc}
CLSID|{2b334c22-40ca-438f-913a-61a8105c4ccd}
CLSID|{2decfcc9-d910-4bac-94b8-fc006827a60f}
CLSID|{356af2e9-8874-4c60-a3d8-0cb516c9e747}
CLSID|{35ba68da-a9f5-4374-8b97-1183d93846a4}
CLSID|{43db73eb-4c90-4418-b6ad-10db22016908}
CLSID|{489b338e-e4ab-489a-91d4-69970a541cf9}
CLSID|{4aa76f27-81bc-4c3f-9f24-cb99349c8cc9}
CLSID|{4f4e2384-42ad-4fe4-b966-b6d50c7bf90a}
CLSID|{5284ac2a-ef00-4750-9b82-b5b907d26536}
CLSID|{59399e33-fb54-48ab-8ae4-ae108b36dab4}
CLSID|{5e19dee2-8d2f-4a9c-a66d-76bbeedd15cb}
CLSID|{5eed48aa-f20f-4085-b8f8-57724b7c5b08}
CLSID|{647b8364-79e0-48e2-a4ca-233abada0c2d}
CLSID|{6813bffd-be81-4613-b4e6-aa7ed0da8659}
CLSID|{68bc55e9-4d3e-4c89-89ac-7559763c98b8}
CLSID|{692ca430-32c8-470d-ba1f-7e15e21e7043}
CLSID|{6ae7418b-229f-4a2c-ae1b-d5962888f02d}
CLSID|{77ca442a-0c72-492b-804a-82611e558142}
CLSID|{7ca36000-3320-49d1-bad1-4c5169d4084a}
CLSID|{7d435027-f646-4bf9-b2c5-0ef4940d5ca2}
CLSID|{7e73c9db-69fb-4580-8e8e-194b34a2306c}
CLSID|{7e7a1949-5c0c-45f3-a106-34fe038493ef}
CLSID|{7f4e63c9-f30c-4424-9baf-b6896f5f56c4}
CLSID|{7fa4ec26-6a28-4474-857d-bb05b001c84a}
CLSID|{8dae9202-0019-4d30-a5d2-aaf02d4ddc37}
CLSID|{8ecc09e1-634b-42ac-8be7-e6edbb53c90e}
CLSID|{94dbdb63-5f05-4c51-8b14-de0ca12ef4ca}
CLSID|{965a8d33-ae18-4c17-8011-fe42d81e0758}
CLSID|{96d58666-8f00-4a9d-9389-c17aaa2407c9}
CLSID|{9dd86cf2-8ac0-4fe0-b55a-601a302b5fd8}
CLSID|{9e87077c-380c-407d-8dab-eedad95c0a5d}
CLSID|{a0e2e5ab-c02f-489b-bd7b-58c329f774f3}
CLSID|{a92616b1-2e82-4052-b579-0a40c2304380}
CLSID|{ae4026cc-b7ba-48e8-8fb3-2c35099670a1}
CLSID|{b0f4bc0f-eaea-43b5-8ce6-dad3cc9b29a2}
CLSID|{b869788c-35df-4104-bacb-8fdb83affffd}
CLSID|{bd9421bb-9f96-4272-802f-49bec746056e}
CLSID|{c033567c-68fe-419b-bcc4-135db7faf8eb}
CLSID|{c7efdcde-a181-41d0-a551-16f73b398040}
CLSID|{c833a552-f5af-4a7b-87b3-6ebde0db3b43}
CLSID|{c85a4afd-ff76-4661-b76a-3e9bb2ce2dab}
CLSID|{cf5c9fce-c963-49e5-a3a4-0a81fffe1e55}
CLSID|{d090e12d-b79c-4b82-a76c-0e3bbe73c9ef}
CLSID|{d80a56d7-451c-41cf-9a74-1447e0887b97}
CLSID|{e0110779-5f79-4685-9c96-9d99efd30ca2}
CLSID|{e73e3959-fb15-44d7-acb9-3a75377006fc}
ID|{e79d5e54-81c9-41ae-9d7b-03f1e5a7733d}
CLSID|{e7ccbd19-2eea-4b6a-b9be-e8a68613809c}
CLSID|{ea0f107f-2bf6-44a0-96c4-a99b74afbc4a}
CLSID|{edf78e1b-31a2-4c6e-ad40-0afcd0d55263}
CLSID|{f585cb1f-f17d-4007-a573-b663197ef500}
CLSID|{f5ab293c-2e21-4441-9ad8-b3646eb26df5}
CLSID|{f5ac8b35-5b15-4e8f-8046-43858973b495}
CLSID|{f63e3b76-f82f-46eb-851c-8c0a221686bb}
CLSID|{f709f572-86f5-47c8-afcf-3cebc468fadb}
CLSID|{f874a0ae-66e8-426b-a3f5-6ba6958dcdba}
CLSID|{f97e5b38-4887-444a-86f5-91c18331500b}
DIREC|
%AllUsersprofile%\Start Menu\Programs\Error Safe\
DIREC|%AllUsersprofile%\Start Menu\Programs\Error Safe Unregistered Version\
DIREC|%AllUsersprofile%\Start Menu\Programs\ErrorSafe\
DIREC|%CommonProgramFiles%\Error Safe\
DIREC|%CommonProgramFiles%\ErrorSafe\
DIREC|%ProgramFiles%\Common Files\ErrorSafe\
DIREC|%ProgramFiles%\Error Safe Free\
DIREC|%ProgramFiles%\errorsafe\
AUTST|Error Safe
AUTST|ErrorSafe
AUTST|ERScw
AUTST|was6_check
CLASS|CompCleanCore.CCQuickScan
CLASS|CompCleanCore.InetCleaner
CLASS|CompCleanCore.RegCleaner
CLASS|CompCleanCore.SystemCleaner
CLASS|df_proxy.DriverManipulate
CLASS|ESCompCleanCore.ESAppCleaner
CLASS|ESCompCleanCore.ESCCQuickScan
CLASS|ESCompCleanCore.ESFileCleaner
CLASS|ESCompCleanCore.ESInetCleaner
CLASS|ESCompCleanCore.ESRegCleaner
CLASS|ESCompCleanCore.ESSystemCleaner
CLASS|ESdf_fixer.ESFixer
CLASS|ESdf_proxy.ESDriverManipulate
CLASS|ESFFWraper.ESFFEnginWraper
CLASS|ESFixCore.ESMMFixCore
CLASS|ESMMFixCtrl.ESCoFixEngine
CLASS|ESSPChck.ESSPChck
CLASS|ESSPCheck.ESSPCheck
CLASS|FlFxr15.FlFixer15
CLASS|FlFxr5.FlFixer5
CLASS|FWraper.FFEnginWraper
CLASS|FxCore.MMFixCore
CLASS|MMFixCtrl.CoFixEngine
CLASS|MMFxCtrl.CoFixEngine
RKSOF|error safe
RKSOF|Error Safe Free
RKSOF|ErrorSafe
UINST|ERS_is1
FILEN|%userprofile%\Desktop\Error Safe.lnk
FILEN|%userprofile%\Desktop\ErrorSafe.lnk
IEZON|errorsafe.com
NEWPR|3531|ExpertAntivirus
PRCAT|43
CLSID|{16dd131d-c09f-4f83-a1e7-a2cf506ea27c}
CLSID|{3e67e9dc-7294-44c3-bc99-ea6e29e74076}
CLSID|{69ebf0db-f6b5-4479-8352-aa632f522d34}
CLSID|{7c1530bd-16b0-41a9-b428-17ee8cbd3e06}
CLSID|{9ec61371-c3b9-fcc1-ee6f-2e4e8d12dffc}
CLSID|{b60f5afa-edd2-417d-a438-57f3ebd9e639}
CLSID|{d59b2dd5-0609-4bdc-ab47-a9a28abc482a}
CLSID|{f82fd7d4-2ec8-40b3-a141-de051c98dce9}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\ExpertAntivirus.Addin.1
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\AdLoader
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Trace7
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\1das\AdLoader
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\dnl7\tracer
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ExpertAntivirus.exe
DIREC|%programfiles%\ExpertAntivirus\
DIREC|%userprofile%\Start Menu\Programs\ExpertAntivirus\
AUTST|ExpertAntivirus
CLASS|ad-protect.EXE
CLASS|ExpertAntivirus.Addin
CLASS|spamdet.DLL
RKSOF|ExpertAntivirus
UINST|ExpertAntivirus
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\ExpertAntivirus v4.1.lnk
FILEN|%userprofile%\Desktop\ExpertAntivirus v4.1.lnk
FILEN|%userprofile%\Start Menu\ExpertAntivirus v4.1.lnk
FILEN|expertantivirus.exe
NEWPR|3501|Fixer AntiSpy
PRCAT|43
DIREC|%programfiles%\Fixer Antispy\
DIREC|%userprofile%\Start Menu\Programs\Fixer Antispy\
AUTST|Fixer Antispy
AUTST|Fixer Antispy Monitor
AUTST|FixerAntispy.exe Monitor
RKSOF|Fixer Antispy
UINST|Fixer Antispy
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\Fixer Antispy.lnk
FILEN|%userprofile%\Desktop\FixerAntispy.lnk
FILEN|fixerantispy.dll
FILEN|fixerantispy.exe
FILEN|fixerantispyinstaller.exe
FILEN|fixerantispy_monitor.exe
FILEN|fixerantispy_updater.exe
NEWPR|3546|Internet Cleanup
PRCAT|43
NEWPR|3107|Kill and Clean
PRCAT|43
CLSID|{4e7883b0-585a-21e2-4dd9-fa16c4875b8c}
CLSID|{bf69df00-2734-477f-8257-27cd04f88779}
DIREC|%ProgramFiles%\KillAndClean
RKSOF|killandclean
UINST|killandclean
FILEN|%USERPROFILE%\desktop\Kill & Clean Scanner and Monitor.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\KillAndClean
FILEN|killandclean.exe
FILEN|killandcleansetup.exe
FILEN|killandcleanupdate.exe
NEWPR|3513|Malware Stopper
PRCAT|43
DIREC|%programfiles%\MalwareStopper\
DIREC|%userprofile%\Start Menu\Programs\MalwareStopper\
AUTST|MalwareStopper
RKSOF|MalwareStopper
UINST|MalwareStopper
FILEN|%userprofile%\Desktop\MalwareStopper.lnk
FILEN|malwarestopper.exe
FILEN|malwarestoppersetup.exe
NEWPR|3305|MalwareWipe
PRCAT|43
NEWPR|2824|MyCleanerPc
PRCAT|43
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\myCleanerPC
DIREC|%allusersprofile%\Application Data\myCleanerPC\
DIREC|%ProgramFiles%\myCleanerPC\
DIREC|%userprofile%\Start Menu\Programs\myCleanerPC\
AUTST|myCleanerPC
RKSOF|VB and VBA Program Settings\MyCleanerPC
RKSOF|VB and VBA Program Settings\MyCleanerPC\Settings
UINST|myCleanerPC
NEWPR|3577|NeoSpace
PRCAT|43
DIREC|%programfiles%\Neospace\
DIREC|%userprofile%\Start Menu\Programs\Internet Security\
RKSOF|Neospace
UINST|Internet Security
FILEN|%userprofile%\Desktop\Internet Security.lnk
FILEN|isec30.exe
NEWPR|3419|PerfectCleaner
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\PerfectCleaner\
DIREC|%programfiles%\PerfectCleaner\
AUTST|PerfectCleaner
RKSOF|PerfectCleaner
UINST|PerfectCleaner
FILEN|%allusersprofile%\Desktop\PerfectCleaner.lnk
FILEN|perfectcleaner.exe
FILEN|perfectcleaner_setup.exe
NEWPR|2853|Pest Trap
PRCAT|43
DIREC|%programfiles%\PestTrap\
WINDO|PestTrap Control Panel
AUTST|PestTrap
RKSOF|PestTrap
UINST|PestTrap
NEWPR|3581|PestBot
PRCAT|43
REGKE|HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\Pestbot
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Pestbot.exe
DIREC|%programfiles%\Pestbot\
DIREC|%userprofile%\Start Menu\Programs\Pestbot\
AUTST|Pestbot
RKSOF|Mandel Enterprise
FILEN|%userprofile%\Desktop\Pestbot.lnk
FILEN|pestbot.exe
NEWPR|3334|PestCapture
PRCAT|43
DIREC|%ProgramFiles%\PestCapture\
DIREC|%USERPROFILE%\start menu\Programs\PestCapture\
WINDO|PestCapture 3.2
AUTST|PestCapture
RKSOF|Install
RKSOF|PestCapture
UINST|PestCapture
FILEN|%USERPROFILE%\desktop\PestCapture.lnk
FILEN|pestcapture.exe
FILEN|pestcapturesetup.exe
NEWPR|2860|Privacy Defender
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\Privacy Defender v4.0\
DIREC|%ProgramFiles%\PrvDef4.0\
UINST|Privacy Defender v4.0
NEWPR|2870|PSGuard
PRCAT|43
CLSID|{01c9453d-0004-43a5-ab44-6aa307c2a0aa}
CLSID|{0bc3bcd5-476d-4be3-a9b9-2225e1b96e90}
CLSID|{1038b941-451a-4a73-b5c0-a9b3243acfbe}
CLSID|{132698d9-0cd6-45e6-8c3f-aa7080a181a1}
CLSID|{15dc7116-e58e-4395-a45a-a1c99b17c030}
CLSID|{17e02586-a91d-4a9d-a74e-187b05dffe6f}
CLSID|{1b1c94e1-cc70-4824-80db-dd7274a66ff1}
CLSID|{1bd98dfd-2da9-4c54-85d7-be03a0f9c487}
CLSID|{1c94ea51-3800-4f08-b5dc-a5b67823ffea}
CLSID|{20d1af34-6e19-42d8-af9f-bdfbe45c2454}
CLSID|{21e132c9-1f98-4151-bdad-7d9b49c60a8e}
CLSID|{23f7ad29-f51a-4ba1-be70-143b1cb25bd1}
CLSID|{28fedb90-53c7-4928-994a-cee782606507}
CLSID|{2c462d06-3ba0-48bb-9282-bb6519fe86e9}
CLSID|{2c59d5ec-6b91-4896-bd6f-5f121d87a7f8}
CLSID|{2f34e0e0-f0bb-477f-afb8-509262fa0ad1}
CLSID|{35ed274e-3f42-4a78-bbdc-3b7d73e85578}
CLSID|{3a350193-c7f7-4e10-b347-02ff4c3cc4e9}
CLSID|{3d74d140-f780-4ae3-8d6d-f8dc39107213}
CLSID|{4723879b-8f52-4be7-9994-626afa539366}
CLSID|{49443d6e-ce4e-47a9-8deb-f5774ce14984}
CLSID|{52034ad2-914c-4634-b375-9299631e5525}
CLSID|{7702c521-76ae-42c0-a181-3b5a96c2eef7}
CLSID|{7adda344-1d36-4446-9f4b-b2351fb19efd}
CLSID|{7b6a3434-8625-4abf-b79d-09d98c2498c4}
CLSID|{7d98221e-af8f-4d29-8bb1-1dfabc288173}
CLSID|{8b6c0168-baac-4c7c-911e-0132590f5661}
CLSID|{8ec33b7d-9953-4edb-ace2-d4c105968601}
CLSID|{9746b450-6064-4ec8-9480-72a289aa2237}
CLSID|{982392f9-9c65-48b4-b667-3459c46630d1}
CLSID|{a00e2305-7001-4200-ba00-5779f9a3e7d3}
CLSID|{a20f5672-7486-4d27-bd2b-e555e4692c5f}
CLSID|{a4b6a8ab-01c1-4f9d-abe1-11a0a574d987}
CLSID|{a917b2f3-a9bf-477c-a0e3-0382d0376159}
CLSID|{b26b5883-f15f-4283-b3d5-a1728077de47}
CLSID|{b803d266-a08d-4a4c-9604-6d35689abe09}
CLSID|{c5a40fce-0a0f-40ca-985e-661c28b5b431}
CLSID|{c6e2a22c-b3a8-43a4-b5ec-a5bb671ab3f7}
CLSID|{c7f22879-7151-4c71-8c50-9557afda66c6}
CLSID|{ca5e7959-60b5-47b7-80ac-1606309733f3}
CLSID|{cabd3101-8501-45b0-928f-86086d66b4b8}
CLSID|{cb9385ab-8541-4b2f-a363-48f64c612993}
CLSID|{ceabf027-6cdc-4d47-adf6-ac5d065826a6}
CLSID|{cf1674cc-ec9a-4aee-996e-65a8f7c0b0e4}
CLSID|{d5d6e9b5-30d5-4457-ac8b-399205f50411}
CLSID|{d6a7d177-0b2f-4283-b2e8-b6310a45e606}
CLSID|{e0aa0493-c410-4cbd-b1db-1723374fa8e0}
CLSID|{e0d6c30a-b9a3-4181-8099-3b0d5a2b98af}
CLSID|{e2605a54-ec78-4618-83d8-bfef45bf370b}
CLSID|{e5d78bd8-3874-4aa0-9d45-cfb79382c484}
CLSID|{e68572c0-6051-4ace-93d3-9981f91da24f}
CLSID|{f100a342-3ac5-47ff-b5b3-fcdb6fc9f016}
CLSID|{f4364eec-31f5-4b8b-a7e0-3b6394c9d23f}
CLSID|{f61d1ce1-5199-4b57-b59e-c6819ea92f3b}
DIREC|%APPDATA%\shudder global limited\psguard\
DIREC|%programfiles%\PSGuard\
RKSOF|ShudderLTD
NEWPR|3540|RegFreeze
CAT|43
CLSID|{635cb2d1-772c-4fcc-af87-ef6c316c9a5a}
CLSID|{76044441-36ea-4e99-a71a-c12070dd13cd}
CLSID|{cdb280e8-be43-4128-8a5a-3fcd094e2d88}
CLSID|{f745f808-e783-4301-8b95-253dc70beefe}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FindExtensions\Static\RegFreeze
CLASS|rfsearchhandler.DLL
CLASS|rfsearchhandler.RegFreezeIEButton
CLASS|rfsearchhandler.RegFreezeSearchHandle
CLASS|rfsearchhandler.RegFreezeSearchHandler
RKSOF|ActualResearch
RKSOF|ADV
UINST|RegFreeze_is1
FILEN|regfreeze.exe
FILEN|rfsearchhandler.dll
NEWPR|2772|Spy-Shield
PRCAT|43
CLSID|{4c824d74-1df5-4058-bd78-203774f09930}
CLSID|{c628512d-a058-4bd4-b47b-b036f45fa02b}
CLSID|{d7abe914-b8cf-4602-9145-6bdaaeda21aa}
CLSID|{df831c0c-f9bc-4e43-8cf4-538f8230e337}
CLSID|{dfcda823-80c5-4f55-b328-7efd4afbd9a0}
CLSID|{ee58659d-4af6-407e-8c88-2f1f45ff8cbd}
REGKE|HKEY_CLASSES_ROOT\AppID\ad-protect.EXE
REGKE|HKEY_CLASSES_ROOT\AppID\spamdet.DLL
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\Spy-Shield.Addin.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Spy-Shield.exe
DIREC|%ProgramFiles%\Spy-Shield\
DIREC|%UserProfile%\Start Menu\Programs\Spy-Shield\
AUTST|Spy-Shield
CLASS|Ad-Protect.Server
CLASS|spamdet.SpamDetector
CLASS|Spy-Shield.Addin
RKSOF|SpyShield
UINST|Spy-Shield
FILEN|%AppData%\Microsoft\Internet Explorer\Quick Launch\Spy-Shield v4.1.lnk
FILEN|%USERPROFILE%\Desktop\Spy-Shield v4.1.lnk
FILEN|%USERPROFILE%\Start Menu\Spy-Shield v4.1.lnk
NEWPR|3425|SpyAway
PRCAT|43
CLSID|{4f65d192-327b-41d6-b082-0d2a104d9b73}
CLSID|{8dd59a91-90a4-4182-8bb5-d545bb5e766f}
CLSID|{d815e42a-0e0b-44b1-8f48-b2e1adbfc3e1}
DIREC|%allusersprofile%\Start Menu\Programs\SpyAway\
DIREC|%programfiles%\SpyAway\
AUTST|SpyAway
CLASS|sa_ie_monitor.ie_monitor
RKSOF|AntiSpyware InstalledApplication
RKSOF|spyaway
UINST|SpyAway
FILEN|%allusersprofile%\Desktop\SpyAway.lnk
FILEN|sa_ie_monitor.dll
FILEN|spyaway.exe
FILEN|spyaway_setup.exe
NEWPR|2361|Spyaxe
PRCAT|43
CLSID|{11853d5f-f894-4cc7-bbc3-fc7a9dcfd896}
CLSID|{2bb3bcbf-411a-4c67-8e69-f4bb301dc333}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\SpyAxe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\SpyAxe.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\spyaxe.exe
DIREC|%programfiles%\SpyAxe\
DIREC|%userprofile%\Start Menu\Programs\SpyAxe\
AUTST|SpyAxe
CLASS|SpyAxe.Backup
CLASS|SpyAxe.EngineListener
CLASS|SpyAxe.Log
CLASS|SpyAxe.LogRecord
CLASS|SpyAxe.Paths
CLASS|SpyAxe.Quarantine
CLASS|SpyAxe.RunAs
CLASS|SpyAxe.Scanner
CLASS|SpyAxe.SearchItem
CLASS|SpyAxe.ThreatCollection
UINST|SpyAxe
FILEN|%userprofile%\Desktop\SpyAxe.lnk
NEWPR|2127|Spybouncer
PRCAT|43
CLSID|{1a0a00f0-3ffe-4e88-944e-3cc8cd1eb3eb}
CLSID|{26b72764-a203-4f29-88e1-8cbc06d2051c}
CLSIA|{4fa3d392-9349-4d85-8fb9-18733534cfe3}
CLSIA|{5e8fd788-c323-4357-ab76-7cbcefba573c}
CLSID|{651d03f0-2655-4d98-a41a-c8d76ad8a1f4}
CLSIA|{7d40adf2-ad68-4959-acec-da96bf5e6eb7}
CLSID|{9a7ef0e4-86f7-41ae-87d3-bfaffcf597e0}
CLSID|{d5515c94-7fe6-4602-8ac9-8e854ba1b766}
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\SpyBouncer\
CLASS|SpyBouncer.SBDownloader
FILEN|%ALLUSERsPROFILE%\Desktop\SpyBouncer.lnk
FILEN|%ALLUSERSPROFILE%\Start Menu\SpyBouncer.lnk
NEWPR|2847|SpyContra
PRCAT|43
DIREC|%ProgramFiles%\SpyContra\
RKSOF|XXI
UINST|SpyContra
NEWPR|3383|Spycrush
PRCAT|43
DIREC|%programfiles%\SpyCrush\
DIREC|%userprofile%\Start Menu\Programs\Spycrush\
AUTST|SpyCrush
RKSOF|Spycrush
UINST|spycrush
FILEN|%userprofile%\desktop\spycrush.lnk
FILEN|%userprofile%\Start Menu\Spycrush 5.1.lnk
FILEN|spycrush.exe
NEWPR|3366|SpyDawn
PRCAT|43
CLSID|{189518df-7eba-4d31-a7e1-73b5bb60e8d5}
CLSID|{2016a466-91a2-43c6-97d8-2fd380f065ef}
CLSID|{23d627fe-3f02-44cf-9ee1-7b9e44bd9e13}
CLSID|{43cfefbe-8ae4-400e-bbe4-a2b61bb140fb}
CLSID|{5790b963-23c5-43c1-bcf5-01c9b5a3e44e}
CLSID|{661173ee-fa31-4769-97d4-b556b5d09bda}
CLSID|{76d06077-d5d3-40ca-b32d-6a67a7ff3f06}
CLSID|{8329660f-e248-4872-98cc-fb9c4fec7ba8}
CLSID|{86c7e6c3-ec47-44e5-aa08-ee0d0a25895f}
CLSID|{9283dac1-43f5-4580-bf86-841f22af2335}
CLSID|{9d635a36-6b3c-4146-8625-f3aaf507bbf8}
CLSID|{ae90cafc-09d4-47f0-9e11-ce621c424f08}
CLSID|{ba397e39-f67f-423f-bc6e-65939450093a}
CLSID|{bec8a83d-01d4-4f15-b8a9-4b4ab24253a7}
CLSID|{c1df2728-8510-0773-96d8-5d0c1f27821b}
CLSID|{c4eedc19-992d-409a-b323-ed57d511afa5}
CLSID|{dd90f677-d205-4f70-9014-659614aabcb2}
CLSID|{e3df91f3-f24f-441e-9001-d61f36024322}
CLSID|{f459eadb-5903-48d5-864c-2b7b46ab1424}
CLSID|{fc4edf66-0547-4f1a-ae96-7cfcad711c90}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyDawn.exe
DIREC|%programfiles%\SpyDawn\
DIREC|%userprofile%\Start Menu\Programs\SpyDawn\
DIREC|%userprofile%\Start Menu\SpyDawn 3.1.lnk
AUTST|didynamia
AUTST|eitheror
AUTST|flammei
AUTST|SpyDawn
RKSOF|SpyDawn
UINST|SpyDawn
FILEN|%APPDATA%\Microsoft\Internet Explorer\Quick Launch\SpyDawn 3.1.lnk
FILEN|%userprofile%\Desktop\SpyDawn.lnk
FILEN|higehsg.dll
FILEN|spydawn.exe
FILEN|xkrdk.dll
NEWPR|2734|SpyFalcon
PRCAT|43
CLSID|{008e3200-28eb-463b-9b58-75c23d80911a}
CLSID|{244b730e-d899-4e38-9428-03d1143242e0}
CLSID|{330a77c2-c15a-43b5-055c-b4e35eaed279}
CLSID|{7a932ed2-1737-4ab8-b84d-c71779958551}
CLSID|{b4e17829-dacb-4320-9abf-dcb382221fc2}
CLSID|{d1a2e7cd-f5c1-21a8-ca2c-13d0ac72d19d}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyFalcon.exe
DIREC|%ProgramFiles%\SpyFalcon\
DIREC|%USERPROFILE%\Start Menu\Programs\SpyFalcon\
AUTST|SpyFalcon
UINST|SpyFalcon
FILEN|%userprofile%\Desktop\SpyFalcon.lnk
FILEN|%userprofile%\Start Menu\SpyFalcon 2.0.lnk
FILEN|atmclk.exe
FILEN|spyfalcon.exe
NEWPR|3426|SpyFighter
PRCAT|43
DIREC|%programfiles%\SpyFighterPro\
DIREC|%userprofile%\Start Menu\Programs\Spy Fighter Pro\
NEWPR|3564|SpyHazard
PRCAT|43
CLSID|{38de4854-bafb-4dff-ae9c-7d6759e1c0a6}
CLSID|{3a4018fd-2a09-4b21-83a0-6f8091f65033}
CLSID|{4a88d502-e8ff-5de6-0799-c215f685c7df}
CLSID|{4c88865f-3df8-4d34-ba45-00e06c12e115}
CLSID|{5af3a36c-3e0f-46bb-b537-7c00c2b86844}
CLSID|{6f0d21e5-07d1-48db-b2a5-4b64f9efd18a}
CLSID|{77947400-c626-4e6b-ba99-9bb374a91993}
CLSID|{86e1cfb9-abe5-467a-895f-c12a121044f8}
CLSID|{88c0cc0d-c111-4025-a35f-f4342ea00d2b}
CLSID|{99acbdc1-b9ae-4841-a892-786099e4958c}
CLSID|{a1cf0bd5-b707-405c-b2b3-57f0de58f4ba}
CLSID|{a6866a37-2485-42a9-acc6-3f1510b56c5f}
CLSID|{a7893ca6-8646-4014-bdb0-dd259b8d01fd}
CLSID|{af0e923a-c1c0-4d81-8c9d-099a3b049383}
CLSID|{d229d3c6-36b8-4459-859c-b00dd467f138}
CLSID|{dcd0837a-79d7-40ff-82cb-6b07204c8fcb}
CLSID|{e05fb96f-5ea9-46de-94b6-d72590d762b5}
CLSID|{e4c445e1-91bc-4152-aa09-54f2553e3a07}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHazard.exe
DIREC|%programfiles%\SpyHazard\
DIREC|%userprofile%\Start Menu\Programs\SpyHazard\
AUTST|SpyHazard
RKSOF|SpyHazard
UINST|SpyHazard
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\SpyHazard 3.1.lnk
FILEN|%userprofile%\SpyHazard.lnk
FILEN|%userprofile%\Start Menu\SpyHazard 3.1.lnk
FILEN|spyhazard.exe
NEWPR|3027|SpyHeal
PRCAT|43
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHeal.exe
DIREC|%ProgramFiles%\SpyHeal\
DIREC|%UserProfile%\Start Menu\Programs\SpyHeal\
AUTST|%userprofile%\Desktop\SpyHeal.lnk
AUTST|SpyHeal
RKSOF|SpyHeal
UINST|SpyHeal
NEWPR|3328|SpyMarshal
PRCAT|43
DIREC|%programfiles%\SpyMarshal\
DIREC|%USERPROFILE%\start menu\programs\SpyMarshal\
WINDO|SpyMarshal 3.2
AUTST|SpyMarshal
RKSOF|SpyMarshal
UINST|SpyMarshal
FILEN|%USERPROFILE%\desktop\SpyMarshal.lnk
FILEN|spymarshal.exe
NEWPR|2852|SpyOnThis
PRCAT|43
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\SpyOnThis\
DIREC|%ProgramFiles%\SpyOnThis\
AUTST|SpyOnThis Monitor
UINST|{B72A13A7-CCCD-407A-882B-4CFC2ADD39EF}_is1
FILEN|%USERPROFILE%\Desktop\SpyOnThis Monitor.lnk
FILEN|%USERPROFILE%\Desktop\SpyOnThis Scanner.lnk
NEWPR|3330|SpySoldier
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\SpySoldier\
DIREC|%ProgramFiles%\SpySoldier\
AUTST|SpySoldier
UINST|SpySoldier_is1
FILEN|%APPDATA%\Microsoft\Internet Explorer\Quick Launch\SpySoldier.lnk
FILEN|%USERPROFILE%\desktop\SpySoldier.lnk
FILEN|%USERPROFILE%\Local Settings\Application Data\SpySoldier
FILEN|spysoldier.exe
FILEN|spysoldier_setup.exe
NEWPR|2692|SpySpotter
PRCAT|43
DIREC|%ProgramFiles%\SpySpotter3\
DIREC|%ProgramFiles%\SpySpotter\
AUTST|SpySpotter
RKSOF|SpySpotter
UINST|SpySpotter
FILEN|%userprofile%\Desktop\SpySpotter.lnk
FILEN|%Userprofile%\Start Menu\Programs\SpySpotter.lnk
FILEN|%userprofile%\Start Menu\SpySpotter.lnk
NEWPR|3569|SpyVampire
PRCAT|43
DIREC|
%userprofile%\Start Menu\Programs\SpyVampire\
DIREC|%programfiles%\SpyVampire\
AUTST|SpyVampire
RKSOF|SpyVampire
UINST|SpyVampire
FILEN|%userprofile%\Start Menu\programs\SpyVampire.lnk
FILEN|spyvampire.exe
FILEN|spyvampire_1.0.1.311_install.exe
NEWPR|2809|Spyware Cleaner
PRCAT|43
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Spyware Cleaner
DIREC|%programfiles%
\Spyware Cleaner\
DIREC|%userprofile%\start menu\programs\Spyware Cleaner\
AUTST|spyclean
RKSOF|SpywareCleaner
UINST|SpywareCleaner
FILEN|%userprofile%\Desktop\SCFree.exe
FILEN|%userprofile%\SCFree.exe
FILEN|spyclean.exe
FILEN|spywinclean.exe
NEWPR|2806|Spyware Quake
PRCAT|43
CLSIA|{00000000-0000-0000-0000-100000000002}
CLSID|{192c5b4a-3efd-40c7-9f99-c472deb8efc0}
CLSID|{1da7dbe8-c51b-4ae4-bc6e-21863349b0b4}
CLSID|{2dd8d482-8f1c-4180-aa8e-9d5819e5f2ea}
CLSID|{411f83b1-a0ec-4155-af99-0137f5efb270}
CLSID|{4e3645af-7a81-4f83-9b8c-1e4f930d873f}
CLSID|{5753791b-f607-48ca-814e-91c14d081f9e}
CLSID|{5b55c4e3-c179-ba0b-b4fd-f2db862d6202}
CLSID|{5e05ea9f-1ea7-4d0b-a09b-d5e29ec758b9}
CLSID|{61032a65-2371-4c89-b5bb-df73090fb5ea}
CLSID|{66189af2-7726-46e8-8628-0f95ab854792}
CLSID|{7070a8f9-08a4-ca47-0ab0-1eb9e4ee1f3b}
CLSID|{7a2f6251-6c99-4da5-9827-954eb45dcb82}
CLSID|{7b4d79df-9ef0-429d-a0e9-d9b138c6a53b}
CLSID|{82c6c396-dd7b-4ce5-b668-c0087d1f3a1f}
CLSID|{853e0d78-f4c2-47cb-a3f5-a774da60dfcd}
CLSID|{860c2f6b-ca82-4282-9187-beccbb66f0af}
CLSID|{89923a78-1dea-41dc-a323-88da2de7b5ae}
CLSID|{8aed5df3-6e0b-4930-b1a5-f8aa8d757497}
CLSID|{94786c47-eb3f-4bd5-a66b-0d49e2c90541}
CLSID|{9989a9bc-9828-467e-af06-e3b279e6e97b}
CLSID|{b2b3702a-5425-489e-a3af-edccafeba019}
CLSID|{c1c56112-2b2e-4d3c-8cfc-7e10c77facef}
CLSID|{ca14ee13-ed15-c4a2-17ff-da4d15c1bc5e}
CLSID|{cd5e2ac9-25ce-a1c5-d1e2-dc6b28a6ed5a}
CLSID|{d01d4aab-22c5-427f-a941-c4b65a3d8a23}
CLSID|{ddb0d689-fae0-4165-9f7c-877602f9dd66}
CLSID|{e2ca7cd1-1ad9-f1c4-3d2a-dc1a33e7af9d}
CLSID|{e5ad5bd5-c710-45e0-abd3-e770fe85dae8}
CLSID|{ea26ce12-de64-a1c5-9a4f-fc1a64e6ac2e}
CLSID|{eb5ca3af-26c1-467b-9a55-2820e0451aab}
CLSID|{ee2975b6-e8d5-405e-8448-8fe9590f6cfb}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareQuake.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler , {E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}
DIREC|%programfiles%\spyquake2.com
DIREC|%ProgramFiles%\SpywareQuake.com\
DIREC|%ProgramFiles%\SpywareQuake\
DIREC|%userprofile%\Start Menu\Programs\SpyQuake2.com
DIREC|%USERPROFILE%\Start Menu\Programs\SpywareQuake\
DIREC|%Windir%\System32\1024\
DIREC|%Windir%\System\1024\
AUTST|bestreak
AUTST|SpyQuake2.com
AUTST|SpywareQuake
AUTST|SpywareQuake.com
RKSOF|SpyQuake2.com
RKSOF|SpywareQuake
RKSOF|spywarequake2.com
UINST|SpyQuake2.com
UINST|SpywareQuake
UINST|spywarequake2.com
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\SpyQuake2.com 2.3.lnk
FILEN|%AppData%\Microsoft\Internet Explorer\Quick Launch\SpywareQuake 2.0.lnk
FILEN|%userprofile%\Desktop\SpyQuake2.com.lnk
FILEN|%UserProfile%\Desktop\SpywareQuake.lnk
FILEN|%userprofile%\Start Menu\SpyQuake2.com 2.3.lnk
FILEN|%UserProfile%\Start Menu\SpywareQuake 2.0.lnk
FILEN|%WINDir%\system32\atmclk.exe
FILEN|%WINDir%\system32\dcomcfg.exe
FILEN|%Windir%\System32\dvdcap.dll
FILEN|%Windir%\System32\sivudro.dll
FILEN|%WinDir%\System32\stickrep.dll
FILEN|%Windir%\System32\suprox.dll
FILEN|%WINDir%\system32\xenadot.dll
SAFEM|QuakeSafeMode
FILEN|spy-quake2.exe
NEWPR|3572|SpyWare Secure
PRCAT|43
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Spyware-Secure
DIREC|%programfiles%\Spyware-Secure\
DIREC|%userprofile%\Start Menu\Programs\Spyware-Secure\
AUTST|Spyware-Secure
RKSOF|Spyware-Secure
FILEN|%temp%\NSIS_SpywareSecure_trial_setup.exe
FILEN|%userprofile%\Desktop\Spyware-Secure.lnk
FILEN|spyware-secure_trial.exe
FILEN|spywaresecure_trial_setup.exe
NEWPR|2850|Spyware Soft Stop
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\Spyware Soft Stop\
DIREC|%ProgramFiles%\Spyware Soft Stop\
AUTST|Software Soft Stop
AUTST|s_reg
UINST|Spyware Soft Stop_is1
NEWPR|2911|Spyware-Wiper
PRCAT|43
FILEN|slimshieldinstall.exe
NEWPR|3461|SpywareLocked
PRCAT|43
CLSID|{02743820-2e7c-42c6-b60c-726d67379edb}
CLSID|{07a582e8-bae3-457d-9d29-2048de45a369}
CLSID|{0b847a1a-a872-95fc-8e22-f8b4ae044657}
CLSID|{15a6894b-53b5-46c0-8c38-050e21ddd201}
CLSID|{17468406-36b6-4bd1-9b6c-3cc320cf28f6}
CLSID|{2f3ff99d-e078-4968-b9c1-87a74c7736cb}
CLSID|{34a0b812-915e-46f2-9f29-df0f0cf97611}
CLSID|{3d8286f5-9606-46c5-89d8-9b6379877732}
CLSID|{46018fd4-1675-4020-85dc-a3a0eeb7bda0}
CLSID|{521c4c7e-d2cf-4eb1-a078-6e126269e0ad}
CLSID|{5a74e275-351b-4072-8f0b-cbe2b7231b37}
CLSID|{655c070f-6724-45bc-bd5e-23609b6d4a3f}
CLSID|{67e054fa-0f1e-4af8-899b-0b52660d7043}
CLSID|{697c34c8-bbac-418c-999a-a5525f4ff8c3}
CLSID|{711c2540-aa7d-4c40-a8c0-9b1bc920378d}
CLSID|{78c9e0da-3bb5-4156-a03c-8326322f10dd}
CLSID|{7f21289a-bb27-49e9-92c3-2bf7910b6072}
CLSID|{80a2bfbd-7906-48ef-9f76-49b9f822393b}
CLSID|{87a8c087-37c2-40c4-9cdf-97437a9f54ba}
CLSID|{88c13519-616e-4a0d-b9ef-441d04891b6f}
CLSID|{8ed3825e-77a7-41d4-bdcb-fd8cc2b0d183}
CLSID|{94e13fca-4bac-4c2a-a5df-746460090f9e}
CLSID|{9d6fac42-a7be-4702-87ef-75d8dc14249e}
CLSID|{a0181cf2-4a15-4cb5-88d7-15eaa2d08a46}
CLSID|{a2e56d03-930a-4bbf-8c8e-4d63d15f88ee}
CLSID|{abae0daf-a6ba-481f-b3ba-0666d0d1b2eb}
CLSID|{b5b6aa2c-f0c7-44b9-a861-261958ecd0b8}
CLSID|{bd8c66a5-617b-4abf-b56d-f547597fe0fa}
CLSID|{cebea6db-dae7-4146-baba-1fbcd1d50426}
CLSID|{d152938d-32e1-43a6-81c7-898502aabf9a}
CLSID|{d675fd26-7200-466f-a380-182fe49af8aa}
CLSID|{d8073d3d-d957-45be-82ca-bb44fd0e9c4b}
CLSID|{dd348ac9-1d04-439a-b451-9a83bd66423b}
CLSID|{deb2fc31-ccc1-4d85-869f-d288e2386dbd}
CLSID|{ef906cf9-6eeb-4626-9a17-2e48c11d2995}
CLSID|{f9a34e6b-4c2a-4f58-b302-79caccd62c5a}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareLocked 3.5.exe
DIREC|%programfiles%\SpyLocked\
DIREC|%programfiles%\SpywareLocked 3.3\
DIREC|%programfiles%\SpywareLocked 3.5\
DIREC|%PROGRAMFILES%\SpywareLocked\
DIREC|%userprofile%\Start Menu\Programs\SpywareLocked 3.5\
AUTST|spywarelocked
AUTST|SpywareLocked 3.3
AUTST|SpywareLocked 3.5
RKSOF|SpywareLocked
RKSOF|SpywareLocked 3.5
UINST|SpywareLocked
UINST|SpywareLocked 3.5
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\SpywareLocked 3.5.lnk
FILEN|%userprofile%\Desktop\SpywareLocked 3.5.lnk
FILEN|%userprofile%\Desktop\SpywareLocked.lnk
FILEN|%userprofile%\Start Menu\SpywareLocked 3.2.lnk
FILEN|%userprofile%\Start Menu\SpywareLocked 3.5.lnk
FILEN|spywarelocked 3.5.exe
FILEN|spywarelocked.exe
NEWPR|2136|SpywareNo!
PRCAT|43
CLSID|{eee7178c-bbc3-4153-9dde-cd0e9ab1b5b6}
DIREC|%ProgramFiles%\Spysheriff\
DIREC|%ProgramFiles%\SpywareNo\
DIREC|%userprofile%\Start Menu\Programs\SpySheriff\
WINDO|SpySheriff Control Panel
AUTST|SNInstall
AUTST|SpySheriff
RKSOF|SNO2
RKSOF|SpySheriff
UINST|SpySheriff
FILEN|%userprofile%\desktop\spysheriff.lnk
FILEN|spysheriff.exe
NEWPR|2869|SpywareSheriff
PRCAT|43
CLSID|{202b0efd-2cb9-039b-2b11-a3579d6d56a3}
CLSID|{7c43e35c-a398-7c5f-b1ba-7e87073be150}
CLSID|{9cb4ce93-8cc7-9e03-1037-2dd837e3a52e}
CLSIA|{d8a8a7f1-53ef-41f2-b44d-f3e2e595dc27}
CLSID|{dfa61db1-388e-4c87-8d56-540fa229bcb4}
DIREC|%allusersprofile%\Start Menu\Programs\SpywareSheriff\
DIREC|%appdata%\SpywareSheriff\
DIREC|%ProgramFiles%\SpywareSheriff\
UINST|spy sheriff
UINST|SpywareSheriff_is1
NEWPR|2438|Spywarestrike
PRCAT|43
CLSID|{0f25878f-f8ae-5d5d-2bb7-31b5f803290d}
CLSID|{0f345791-d507-4f1c-9e44-8beec61d6148}
CLSID|{15462503-7597-4662-9c63-31c42112d4e9}
CLSID|{17412fea-fb37-4fc0-b689-dcf84fc7fb0a}
CLSID|{27150f81-0877-42e9-af13-55e5a3439a26}
CLSID|{2c15cdea-3ef4-4405-90b0-19a1389b36ed}
CLSID|{3115a433-3fa0-483b-ab01-2a61c951fe58}
CLSID|{4dc8dca1-191d-4bd9-bcfe-44df358ae036}
CLSID|{51fefa9c-1d5a-41c4-81fe-8c0fbe9254f0}
CLSID|{5b395871-7173-4b84-986a-a7112f1bdb45}
CLSID|{5ccc8d01-9f75-4f07-9acf-deb314176c79}
CLSID|{5e7bf614-960b-4a1f-9236-9ec01ac4c5e2}
CLSID|{66f0ac1c-ded5-4965-9e31-39788df1b264}
CLSID|{72daa86e-db4a-42b0-b82a-41a6de2b315e}
CLSID|{732eb0fc-c608-40b1-b524-b092e3915316}
CLSID|{849e056a-d67a-431e-9370-2275f26d39b5}
CLSID|{8504b09f-e628-4af9-8f8f-f2f73e4b46ab}
CLSID|{8b7afbfd-631c-45ba-9145-f059eb58dd73}
CLSID|{8d6083dc-ad33-44db-a8f1-b3b520af9891}
CLSID|{900fe140-70c1-4043-b32d-c89412399fb6}
CLSID|{95a5de55-9979-4507-a521-2e1f8bcc61ab}
CLSID|{a1c155d5-80a0-4bf2-ac7a-53b027c47879}
CLSID|{afeb8519-0b8b-4023-8c15-ffb17d5225f9}
CLSID|{b5775c39-bfef-4fa2-a194-550807a95146}
CLSID|{ba9cc151-4581-438e-94af-4c703201b7ca}
CLSID|{bc74c336-ff2c-40c9-ad4e-3772c208406b}
CLSID|{bdf00f24-a571-4392-95ec-04fdff82a82c}
CLSID|{c1a4c0c9-dbd0-493a-93f8-0b05edc96224}
CLSID|{c4e953e6-770e-4f59-a5e3-43e9f0d682e2}
CLSID|{ca8beb64-4a47-411b-87a1-488643df9521}
CLSID|{d0ab917d-1645-4eeb-b9bb-b33103845ed9}
CLSID|{e0105e7c-d0c4-4dea-aa21-b02f2960ecaf}
CLSID|{e809d2ae-7550-4540-bd5c-4e214ee86661}
CLSID|{ed39cb7c-1bf6-429b-a275-f183b4a3efcb}
CLSID|{ed9f5c8f-c607-4928-9d6c-47484e9a0fee}
CLSID|{f23aa637-31d5-4526-b5c6-9ff89e16202c}
DIREC|%programfiles%\Spyware Strike\
AUTST|SpywareStrike
FILEN|spywarestrike.exe
FILEN|ss_setup.exe
NEWPR|3530|StartGuard
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\StartGuard\
DIREC|%programfiles%\StartGuard\
DIREC|%windir%\SGQuarantine\
AUTST|StartGuard
RKSOF|StartGuard
UINST|StartGuard Free Edition_is1
FILEN|%userprofile%\D
esktop\StartGuard.lnk
FILEN|%windir%\SGPro.exe
FILEN|%windir%\SGPro.log
FILEN|sgpro.exe
FILEN|sg_free.exe
NEWPR|3049|SystemDoctor 2006
PRCAT|43
CLSIA|{09f1adac-76d8-4d0f-99a5-5c907dadb988}
DIREC|%allusersprofile%\Start Menu\Programs\SystemDoctor 2006 Unregistered Version
DIREC|%programfiles%\systemdoctor 2006 free
CLASS|SystemDoctor.Free
RKSOF|SystemDoctor 2006 Free
UINST|USDR6_is1
FILEN|%windir%\downloaded program files\usdr6_0001_d08m0404netinstaller.exe
IEZON|http://*.systemdoctor.com
IEZON|systemdoctor.com
FILEN|sd2006.exe
FILEN|systemdoctor2006freeinstall.exe
FILEN|systemdoctorfreesetup.exe
NEWPR|2607|SystemStable
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\SystemStable\
DIREC|%ProgramFiles%\SystemStable\
UINST|SystemStable_is1
NEWPR|2934|Titan Shield Antispyware
PRCAT|43
CLSID|{5e8fa924-def0-4e71-8a82-a11ca0c1413b}
NEWPR|2929|TrustCleaner
PRCAT|43
CLSID|{24e27ea9-fcf3-444f-bd80-20543ba5d946}
DIREC|%ProgramFiles%\Trust Cleaner\
DIREC|%userprofile%\Start Menu\Programs\Trust Cleaner\
AUTST|Trust Cleaner
RKSOF|Trust Cleaner
UINST|Trust Cleaner
UINST|Trust Cleaner Promo
FILEN|%userprofile%\Desktop\Trust Cleaner.lnk
SERVK|TrustCleanerDriver
NEWPR|3174|Ultimate Cleaner
PRCAT|43
DIREC|%ProgramFiles%\Ultimate Cleaner\
AUTST|Ultimate Cleaner
NEWPR|2904|Ultimate Defender
PRCAT|43
DIREC|%allusersprofile%\start menu\ultimate defender
DIREC|%appdata%\ultimate defender
DIREC|%programfiles%\ultimate defender
AUTST|a856cdb1.exe
AUTST|Ultimate Defender
RKSOF|ultimate defender
UINST|ultimate defender
FILEN|%userprofile%\desktop\ultimate defender.lnk
IEZON|flingstone.com
NEWPR|2813|UnSpyPC
PRCAT|43
CLSID|{bf69df00-4734-477f-8257-27cd04f88779}
DIREC|%ProgramFiles%\UnSpyPC\
DIREC|%userprofile%\Start Menu\Programs\UnSpyPC\
AUTST|UnSpyPC
RKSOF|UnSpyPC
UINST|UnSpyPC
FILEN|%userprofile%\Desktop\UnSpyPC Scanner & Monitor.lnk
NEWPR|514|Virtual Bouncer
PRCAT|43
CLSID|{0990e9a3-fc49-4aa8-91ce-f738bcbb7c8f}
CLSID|{13c243a0-50e9-43f4-8e5b-9ff857c3a0b5}
CLSID|{18bbdf4d-611d-41ce-a7e7-b2dd23c250d1}
CLSID|{25ae1a9b-87d2-418f-a3a6-5a46edc37a84}
CLSID|{261214cb-3021-4de0-9d21-5957acd1781a}
CLSID|{2c2ebd54-ed76-4343-902b-336d1db63763}
CLSID|{36c9c487-e14f-4bb9-9882-ac613193ee46}
CLSIA|{41f31718-2b9d-4f76-85e2-dd11bba99f8d}
CLSID|{4a277e1b-b130-4e4a-92ae-8712f4a150bd}
CLSID|{4b795337-d704-49c7-8ca1-d65722b28ebd}
CLSID|{6a4c71b1-1a79-483a-a400-f026936cc7b7}
CLSID|{6cdc3337-01f7-4a79-a4af-0b19303cc0be}
CLSID|{6d37ded8-1944-4e32-93fd-b9610e0ad8e3}
CLSID|{6e0ed53c-9908-49ed-b055-7cb31b162577}
CLSID|{73d7abfe-d325-430a-817f-64c7bfd48813}
CLSID|{795398d0-dc2f-4118-a69c-592273ba9c2b}
CLSID|{8551311d-f3bf-4718-ad66-96e302500735}
CLSID|{85d1e607-0c1a-4e69-ba9b-2e5ffa382d68}
CLSID|{88eb5b21-0fe7-4208-8f1c-26915f7e2432}
CLSID|{8940e505-72c6-44de-be85-1d746780efbf}
CLSID|{8c53bd8e-b12d-4c8f-ad0e-c9ddc39d1273}
CLSID|{8c7ab65b-830c-442a-a71a-0e06baf9caf2}
CLSID|{8dd9b882-0041-449d-a0bd-77a87119ad90}
CLSID|{92dd4b20-de93-4f74-8bca-ec7f88fdac5d}
CLSID|{934e4898-de90-45e1-adf4-c383dcae7b26}
CLSID|{950695da-8f77-4852-ad93-8c1e64995d4b}
CLSID|{9bcdd51b-4a7b-446c-8452-d32d38004582}
CLSID|{9cc6f6d3-8b13-4206-abc1-8b285f9413a7}
CLSID|{9fe4d9e6-13bb-43e0-8c74-9800573da4d6}
CLSID|{a85c505e-aae3-4cb0-aee1-cb8213b140fb}
CLSID|{a986f4db-792e-4571-8974-0bb6e024766f}
CLSID|{b0be4bbc-c1b6-4ea3-b346-7358fec20248}
CLSID|{be05f07d-131c-4935-941b-0d41ceb07e67}
CLSID|{be40278c-1c4e-4a63-bc3d-811646900a1a}
CLSID|{ce23505d-68fb-4c49-ae4b-d4f1cf86a2c4}
CLSID|{cf0fbbf5-1ddd-4d58-b480-ac2c2a4186d3}
CLSIA|{d9ec0a76-03bf-11d4-a509-0090270f86e3}
CLSID|{db90dea9-0897-4b02-9fe0-1e321a22eab0}
CLSID|{db92433d-1902-4789-bafc-b46b0dcdebb7}
CLSID|{dcb5773b-4d84-4e6f-8e21-96f2a5b431a8}
CLSID|{e2b951f0-9f32-4260-90f7-a988beff7f0c}
CLSID|{ec352548-52b5-41ac-b8c1-8cb561ecf7ad}
CLSID|{eec056ce-3e1b-4571-bee1-eab9876b35f8}
CLSID|{f3a1bec7-6d42-4a5d-abdc-534669a087e1}
CLSID|{f634e01a-833a-49fb-bae2-3a00cecc3a94}
REGKE|HKEY_CURRENT_USER\Software\VB and VBA Program Settings\VBouncer
DIREC|%allusersprofile%\application data\VBouncer
DIREC|%APPDATA%\vbouncer
DIREC|%programfiles%\bouncer
DIREC|%ProgramFiles%\Bouncer\
DIREC|%programfiles%\VBouncer
DIREC|%userprofile%\start menu\programs\Virtual Bouncer
AUTST|Bouncer RunStartup
AUTST|VBouncer
AUTST|VBundleOuterDL
AUTST|vcmxin
CLASS|VBDNR.cCookie
CLASS|VBDNR.cErrorLog
CLASS|VBDNR.cHistory
CLASS|VBDNR.cRegistryRoutines
CLASS|VBDNR.cScheduler
CLASS|VBDNR.cSignature
CLASS|VBDNR.cThreatLevel
CLASS|VBDNR.cUserSettings
CLASS|VBDNR.DNRDirector
RKSOF|VBouncer
UINST|Virtual Bouncer
FILEN|bundleouter2601031121.exe
FILEN|swrt01.dll
FILEN|vb2uninstaller4_19.exe
FILEN|vbdnr.dll
FILEN|vbouncerinner.exe
FILEN|vbouncerinner1007.exe
FILEN|vbouncerinner1106.exe
FILEN|vbouncerinner1107.exe
FILEN|vbouncerinner1108.exe
FILEN|vbouncerinner1109.exe
FILEN|vbouncerouter1123030429.exe
FILEN|vbouncerouter1203.exe
FILEN|virtualbouncer.exe
FILEN|virtual_bouncer.exe
NEWPR|3058|VirusBlast
PRCAT|43
CLSID|{0d0fab5c-2be4-4126-a28e-828febce1e55}
CLSID|{1131081d-81ed-46f0-8b03-b728aeaffd12}
CLSID|{1f6fe2c2-6040-4645-9053-7f689affe176}
CLSID|{214345b8-bb69-498d-a168-29f58f15d806}
CLSID|{283ed043-d403-4808-bf28-fcde29dcf1fb}
CLSID|{490e7d57-1fc1-4ea6-bd52-483b7271b223}
CLSID|{6994ad04-93ef-11d0-a3cc-00a0c9223196}
CLSID|{80ed1eb2-55fb-4434-bd41-e1645a370158}
CLSID|{9da04bbd-71bb-020c-436e-42fecbb98f05}
CLSID|{9da1990b-9bca-4c80-aefb-11a40fa849f9}
CLSID|{e6b4ab50-f423-4ee6-9839-b35dcfcdfa49}
DIREC|%programfiles%\virusblast\
AUTST|VirusBlast
RKSOF|VirusBlast
UINST|VirusBlast
NEWPR|3299|VirusBurst
PRCAT|43
CLSID|{0249beb1-a2aa-45a3-9ec5-95d9c4a40a62}
CLSID|{02a40ea7-b5b4-4f41-b2ff-2a8a0aec50cf}
CLSID|{082da6af-f994-4c6c-a2b0-dfc3b3ff540a}
CLSID|{0c25003b-f5c9-4c24-a5f8-5bee543a562c}
CLSID|{0c9a71b1-8a8a-48a1-aa3f-0c83ce1c0bbd}
CLSID|{0ef25077-da22-4ff2-b6ff-6fc1c26f5740}
CLSID|{150d28ac-7c2d-4b57-b837-c74dce7cc728}
CLSID|{20dc1f8e-4640-4fff-9858-05e7b978cc71}
CLSID|{2613cf74-4fc5-4251-9f48-260496364852}
CLSID|{276d86b8-010b-4576-8444-9a670070a3f4}
CLSID|{27d8cd06-82e3-4e1e-8917-86a9b3ae41f6}
CLSID|{2d9caf75-4b36-455b-adef-0cfd7adf3154}
CLSID|{38cd62aa-98ac-4b47-9cb8-8e1f108ad32f}
CLSID|{3b021ad8-9999-4efe-8203-36a5b09117d7}
CLSID|{3c975d06-9239-4a00-9f1a-c3c337912f22}
CLSID|{413d2fa5-98cd-4078-98c1-c3ae775ef050}
CLSID|{41f834da-af4b-4c04-bd2e-9fa131ff39e5}
CLSID|{46722628-c282-4fdf-814d-5b819c78e067}
CLSID|{48ce44bf-e439-46de-8cd8-88cb5b3d6d6e}
CLSID|{49a6d89f-4422-4474-a287-5fe1d6811a87}
CLSID|{4d993022-0899-4599-b4b6-0f887d0802e6}
CLSID|{4f7fa7bf-007c-46e6-a49c-b8e7373c046e}
CLSID|{4fc003c3-87a0-489c-85cd-878246eb2d18}
CLSID|{5f412259-081e-4b21-815d-93ae1e71ae95}
CLSID|{66b01f8a-1d57-40e7-8c8d-d67d06662577}
CLSID|{6a66cc28-f0a2-fcbc-d3d5-1ea3001ed26a}
CLSID|{7588c5e3-9c6e-4cfe-884f-71bf8383621a}
CLSID|{78ea0c93-1aaa-4922-84f0-42cba685f6bc}
CLSID|{7caefbcd-55a9-4a68-aa02-e69b12b3be57}
CLSID|{8122d5a8-dc59-4ab8-9c02-cf66e10641c2}
CLSID|{887d7071-fb68-49f6-a77c-e12d0a83bf91}
CLSID|{898272cf-3ace-4a7b-98fa-9eb8db8b26dc}
CLSID|{8cbf5bac-e609-4863-abc9-68a7bd13b1d0}
CLSID|{8fb11528-3a97-45fe-beaa-1a1fc4ee45f5}
CLSID|{8fe88dc0-e1ec-43e3-b70e-d3246f4d1899}
CLSID|{9981ddef-81c4-4cc8-a5f2-62a7912d8037}
CLSID|{9cb68df7-f336-45a2-bde2-5dca3998986f}
CLSID|{9ecef347-16e8-45b3-bb6d-ae9ddfc4ec11}
CLSID|{9ee20753-220c-4a2c-87dc-f86fb78f3774}
CLSID|{a25f0022-c2fc-4ea0-abba-2bfe4635bd68}
CLSID|{a4bb2045-c8b4-4a9f-b509-7a626797b961}
CLSID|{a537df83-75f0-e83c-5665-e5e8f23f996e}
CLSID|{b4bb620f-3ae7-4910-8171-f9fc8120d9ef}
CLSID|{bdc75ad7-a8a5-4f25-be36-a4db971c7541}
CLSID|{bed38b7d-66e0-47b2-a7ef-8682b62828d6}
CLSID|{c49930c7-abf8-43b4-a7b7-98013dd6abe6}
CLSID|{c97c3b7c-e022-4fa8-b1a7-1c28270ffaff}
CLSID|{d838d7a3-1551-4b32-bf7a-7f4f769bb885}
CLSID|{d87a739b-ad9a-4973-b8c5-9d55b3ec0401}
CLSID|{e1751f23-00e6-4f6c-ad78-ca7d8a96fd3e}
CLSID|{ec6921c1-f723-49c9-b760-274de8238ed6}
CLSID|{eca9fbff-5415-4440-a92b-03e8ca7b9828}
CLSID|{ed639b1f-1b3f-473f-bd8d-6de9c2d1972a}
CLSID|{f31aee4a-1530-4fef-8537-79c6973bff9a}
CLSID|{f7996a4a-b172-4c1a-85d0-19ab61c9c512}
CLSID|{f83e8f99-ae49-45d6-92b4-59854bf0a759}
CLSID|{fbea0445-4c4a-4136-864a-c72a4a182a84}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\virus-bursters.exe\
DIREC|%programfiles%\Virus-Bursters\
DIREC|%USERPROFILE%\Start Menu\Programs\Virus-Bursters\
WINDO|Virus-Bursters 6.3
AUTST|Virus-Bursters
RKSOF|Virus-Bursters
UINST|Virus-Bursters
FILEN|%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Virus-Bursters 6.3.lnk
FILEN|%USERPROFILE%\Desktop\Virus-Bursters.lnk
FILEN|%userprofile%\Start Menu\Virus-Bursters 6.3.lnk
FILEN|vb_distrib.exe
FILEN|virus-bursters.exe
NEWPR|3699|VirusProtectPro
PRCAT|43
CLSID|{049fece3-18c7-4023-a1be-cfaa2c4ee387}
CLSID|{07420914-e5a0-451e-bfd4-aa1b799d39ad}
CLSID|{0b6c7539-c6d5-4dde-9632-184f421ef8d7}
CLSID|{164913b3-fcde-45b5-8901-1750f4e3119e}
CLSID|{1d52bb09-465c-4aa4-9fbd-71d1690caed3}
CLSID|{24998748-6e8a-40d1-aa97-e9952ee9ed18}
CLSID|{287ffe0c-15d0-4bfd-baa9-0582c6361bbb}
CLSID|{365036eb-87c2-4627-8fbc-ef6e9e
8da5c2}
CLSID|{45973d31-5ce3-4503-bc81-25e525119c48}
CLSID|{45c2fdbe-1d46-b98e-f9a9-9d44b93a9d52}
CLSID|{46d4d563-1c43-4cee-af98-471385f2bc42}
CLSID|{5596a310-2e54-4b75-ada3-7ee0ad10e228}
CLSID|{5c17f7d3-8460-4488-84eb-986a38bedd2d}
CLSID|{64d6666f-b95e-4048-9fa5-f68b094ea030}
CLSID|{69b73aa0-ca0c-4be6-9811-eb0d951b5b99}
CLSID|{6d88033c-6fd8-4374-9532-7ea301df08ae}
CLSID|{71df187c-dc99-4a35-bdb2-c099821a435d}
CLSID|{74df3f5e-99d7-4f4d-81c3-95201d4cda88}
CLSID|{77345588-ab75-4cda-873f-aae78c01efcd}
CLSID|{91478017-ff82-4c5d-9fff-7801f8d99ccc}
CLSID|{9af8f31b-b778-4413-b8ed-ae63a62e1f7d}
CLSID|{9f9c8cf3-eb4a-4851-a4f6-2370f5bc79ee}
CLSID|{b1b9c911-ca24-4e1e-9f56-838486218327}
CLSID|{b56ed873-c3d3-4202-9ef8-fb31dee2c207}
CLSID|{bb3ebaf2-f4c4-4b66-9a98-eed3b70d1bb3}
CLSID|{c5cc0894-ad1e-47ad-9265-0f463ae30508}
CLSID|{c7604d71-cd16-4976-9383-d24b6fad052e}
CLSID|{c78e49c0-ab82-4c79-a189-f1e34980643b}
CLSID|{d2a0598f-fbc4-4721-bc85-f75c0712c100}
CLSID|{d42cf3bb-e79e-4c0b-b434-6841ca9c4593}
CLSID|{d8c36036-2e41-4ce0-9351-99087dd28a29}
CLSID|{e60a0f09-dd6b-4343-84b0-c33b946d5a9c}
CLSID|{e6369bca-e4fa-4497-89c5-ecf9268b64b1}
CLSID|{e7b2831e-a25a-430b-b3e3-3d414f9c4288}
CLSID|{edc652ff-2ea2-4e46-8849-d9041b77b88e}
CLSID|{f040e242-bad6-46f7-a787-d3ab811e5bc3}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\VirusProtectPro 3.4.exe 3.4
DIREC|%programfiles%\VirusProtectPro 3.4\
DIREC|%userprofile%\Start Menu\Programs\VirusProtectPro 3.4\
AUTST|VirusProtectPro 3.3
AUTST|VirusProtectPro 3.4
RKSOF|VirusProtectPro 3.4
UINST|VirusProtectPro 3.4
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\VirusProtectPro 3.4.ln
FILEN|%userprofile%\Desktop\VirusProtectPro 3.4.lnk
FILEN|%userprofile%\Start Menu\VirusProtectPro 3.4.lnk
FILEN|VirusProtectPro 3.4.exe
NEWPR|1818|Wareout
PRCAT|43
DIREC|%appdata%\Start Menu\Programs\WareOut
DIREC|%ProgramFiles%\WareOut
AUTST|backorif
AUTST|bingo9
AUTST|ERTYDF
AUTST|ExchangeMaster
AUTST|EXE32EXE
AUTST|ftbar
AUTST|hclean32.exe
AUTST|JAguAr
AUTST|jopplerg
AUTST|newbreed
AUTST|NsCplTray
AUTST|ParisM
AUTST|TemplateDongle
AUTST|Trayz
AUTST|uio
AUTST|UserSp1
AUTST|WareOut
AUTST|WhatsNewBot
RKSOF|WareOut
UINST|WareOut
FILEN|%appdata%\Desktop\WareOut Scanner & Monitor.lnk
FILEN|wareoutupdate.exe
NEWPR|2741|WinAntiSpyware
PRCAT|43
CLSID|{2b798a44-7dfc-4c46-bd8f-41259d169a0d}
CLSID|{328ba26a-1619-47ee-a37d-7d7a6ab1b000}
CLSID|{4d05a335-1a1c-46b3-bcff-7f25b326895c}
CLSID|{8576de55-eded-4675-af10-ba15eddb4d7a}
CLSID|{d4c0649b-b980-44a5-b259-9b09ebea6331}
CLSID|{e69f0d6a-1c69-4a04-8709-5eac2019d9be}
CLSID|{fc0b8eb8-ae24-4fd6-b479-e2b464f32da6}
DIREC|%allusersprofile%\Start Menu\Programs\WinAntiSpyware 2005\
DIREC|%ProgramFiles%\Common Files\WinSoftware\
DIREC|%ProgramFiles%\WinAntiSpyware 2005\
AUTST|WinAntiSpyware 2005
RKSOF|WinSoftware\WinAntiSpyware 2005\
FILEN|%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinAntiSpyware 2005.lnk
FILEN|%userprofile%\Desktop\WinAntiSpyware 2005.lnk
NEWPR|2731|WinAntiVirus
PRCAT|43
CLSID|{025c9956-0606-4583-bc40-633904ff6d77}
CLSID|{11d14da6-fcaa-405e-b014-e5920f922ac1}
CLSID|{1bd800a1-1c40-47e6-99a1-22b04dab2ce0}
CLSID|{2178f3fb-2560-458f-bdee-631e2fe0dfe4}
CLSID|{26ea10bd-85b6-4052-9300-59aac07e84ef}
CLSID|{3f9d0c61-737d-44d1-bd80-91af857061cc}
CLSID|{406b7088-1e9d-48c4-b7b2-4ff9738997ab}
CLSID|{4e34ab3c-05d2-438e-a408-06cb9467038d}
CLSID|{5d65f8b9-6c63-4227-ab90-04e8d2b87c31}
CLSID|{5f4c4961-505d-4da5-b770-bf3d860c0207}
CLSID|{62b74dc2-2c6f-4dae-9e39-fffb8018c47b}
CLSID|{66ba5dc6-bba9-470f-a68d-37ccd9ab6788}
CLSID|{82b9a1fb-6b6b-47d2-8ced-b9a494f26f48}
CLSID|{8aa798d6-fa74-43d3-8121-321b21cb9c3b}
CLSID|{8acf7e80-3254-4f9a-9d11-39e10e04973a}
CLSID|{989adb33-3ee9-4a36-8113-76d1b79b606b}
CLSID|{b5141620-c2b2-4d95-9f0f-134d99c87ab0}
CLSIA|{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a}
CLSID|{bad54733-5051-485e-b8f0-8a78bebd80fc}
CLSID|{c0a3779c-3345-4150-bd63-c399eb32661e}
CLSID|{feb5c757-2f1d-4939-a069-42564648403b}
DIREC|
%ProgramFiles%\Common Files\WinAntiVirus pro 2006\
DIREC|%allusersprofile%\Application Data\WinAntiVirus Pro 2007\
DIREC|%allusersprofile%\Application Data\WinSoftware\WinAntiVirus 2005\
DIREC|%allusersprofile%\Start Menu\Programs\WinAntiVirus 2005 Trial\
DIREC|%allusersprofile%\Start Menu\Programs\WinAntiVirus 2005\
DIREC|%allusersprofile%\Start Menu\Programs\WinAntiVirus Pro 2007\
DIREC|%ProgramFiles%\Common Files\WinAntiVirus 2005 Trial\
DIREC|%ProgramFiles%\Common Files\WinAntiVirus 2005\
DIREC|%ProgramFiles%\Common Files\WinAntiVirus Pro 2007\
DIREC|%ProgramFiles%\WinAntiVirus 2005 Trial\
DIREC|%ProgramFiles%\WinAntiVirus 2005\
DIREC|%programfiles%\WinAntiVirus Pro 2006\
DIREC|%ProgramFiles%\WinAntiVirus Pro 2007\
DIREC|%userprofile%\Application Data\SystemDoctor 2006 Free\
DIREC|%userprofile%\Application Data\WinSoftware\WinAntiVirus 2005\
AUTST|%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinAntiVirus 2005.lnk
AUTST|%userprofile%\Desktop\WinAntiVirus Pro 2007.lnk
AUTST|DNSE
AUTST|fat.exe
AUTST|mav_startupmon
AUTST|Nls
AUTST|rtasks
AUTST|runner1
AUTST|uwa6pcw
AUTST|uwa7pcw
AUTST|WinAntiVirus Pro 2007
AUTST|winantivirus.com
AUTST|WinAntiVirusPro 2007
AUTST|WinAntiVirusPro2006
CLASS|AntiVirusCOM.AVOfficeProtect
CLASS|IEFWBHO.IEFW
RKSOF|WinAntiVirus Pro 2007
RKSOF|winsoftware\winantivirus 2005
RKSOF|winsoftware\winantivirus 2005 trial
FILEN|%Allusersprofile%\Desktop\WinAntiVirus Pro 2006.lnk
FILEN|%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinAntiVirus 2005 Trial.lnk
FILEN|%userprofile%\desktop\remove spyware.url
FILEN|%userprofile%\Desktop\WinAntiVirus 2005 Trial.lnk
FILEN|%userprofile%\Desktop\WinAntiVirus 2005.lnk
SERVI|FWSvc
IEZON| http://www.winantivirus.com
IEZON| http://www.winantiviruspro.com
FILEN|winantiviruspro2006freeinstall.cab
NEWPR|2263|WinFixer
PRCAT|43
CLSID|{08c71fb1-1e66-4d22-9f32-4c045a451306}
CLSID|{0e9f6ac0-a21a-4591-910f-e2c6f3ca094c}
CLSID|{1cdeb41b-905a-4183-aa20-26e075419b46}
CLSID|{1ce1c25b-f8b4-4974-99d2-5d4ae96b9900}
CLSID|{25a3c995-10c8-474b-a167-99460ab4ab2b}
CLSID|{287a2bad-6590-4eff-9bbc-494385664a73}
CLSID|{290b5b73-4963-4ba1-9d2d-07cb566cb7fa}
CLSID|{30ed49a5-ca6c-4918-b5f3-5e6818c91d8b}
CLSID|{3496d13a-609a-407b-b181-8f47b4f28ae9}
CLSID|{35096c29-3507-4abe-b6d8-c7cc881be020}
CLSID|{38edb9e2-d7c4-4575-8905-fe65414ffead}
CLSID|{38f743a2-210f-49de-9b79-dcd501ced284}
CLSID|{3eec290d-fc13-4c83-803d-4802651eeb61}
CLSID|{41a5bbf6-3c9d-4cf9-9a99-32dd37cc290b}
CLSID|{48349992-1402-4c67-b45b-2e619e641fdb}
CLSID|{4dceea42-794d-4855-9ecc-20dcf5f4fea7}
CLSID|{4e4f38d9-8736-41ae-b192-e829ae194398}
CLSID|{4f79d1c5-24f9-4e59-8022-604d4b41d5ca}
CLSID|{538bc8f3-2e1e-4d2d-a261-158df6e9b407}
CLSID|{66484903-09f4-4330-927d-1f6c214221ac}
CLSID|{6a077841-5016-42c8-92c8-f2d6b865bcd1}
CLSID|{6dd0bc06-4719-4ba3-bebc-fbae6a448152}
CLSID|{7fa14ad6-d8e5-465f-9bd1-a37e26c1a74f}
CLSID|{8c65aef6-e413-4314-815b-82717a3f1603}
CLSID|{9e984934-cd94-4763-9dbc-618e483d4b7f}
CLSID|{ad70ac89-f460-4e7e-b5a5-7eaf7e207736}
CLSID|{b115bd8e-b008-46f4-b8b6-3405eb325c3c}
CLSID|{b5e427f9-ab38-4348-9076-86870c2be860}
CLSID|{b6625280-8cd8-4632-97c0-83cec12a49a3}
CLSID|{b9dfcf32-b679-4cad-b7fc-518a48ce3922}
CLSID|{cae8a9b1-abbd-4159-a485-1da045a5d4a1}
CLSID|{cbeef194-ebc5-4758-9b51-ac34fc135e70}
CLSID|{cd3604cc-2b95-43ee-afc9-e7444c21be1c}
CLSID|{ce70731d-f28d-4d81-9d61-c8ee60378401}
CLSID|{d21040fe-0a57-4fab-8ed2-f0e653e55809}
CLSID|{d7a2488e-53e4-4edd-aeaa-f24778beb100}
CLSID|{d7a6df8d-b6cf-4c27-8e99-eca2ce370ea7}
CLSID|{e8928e69-c050-42a9-8884-94de85e888a2}
CLSID|{f41c1430-cfde-4ad3-b38d-7890f0843e47}
CLSID|{f458adae-d53b-4859-b99f-9fa127791278}
CLSID|{f6c1582e-b11c-4724-b8f6-240457ef1d2a}
CLSIA|{f919fbd3-a96b-4679-af26-f551439bb5fd}
CLSID|{fb787d5e-0c7c-4bab-b45d-20325fb886db}
CLSID|{fc76a5b8-db35-4f3e-8b9a-bf0eea098d64}
DIREC|%allusersprofile%\start menu\programs\winfixer 2005\
DIREC|%commonprogramfiles%\winsoftware\
DIREC|%programfiles%\winfixer 2005\
DIREC|%programfiles%\winfixer2005\
AUTST|NI.UWFX5
AUTST|NI.UWFX5_0001_LP1014
AUTST|NI.UWFX5_0001_NI53TEST
AUTST|WinFixer 2005
AUTST|WinFixer2005
CLASS|compcleancore.appcleaner
CLASS|compcleancore.filecleaner
CLASS|df_fixer.Fix
CLASS|df_fixer.fixer
CLASS|ffcom.flfixer
CLASS|ffwraper.ffenginwraper
CLASS|fixcore.mmfixcore
CLASS|FlFxr.FlFixer
CLASS|MMFx.CoFixEngin
CLASS|UWFXPCheck.UWFXPCheck
RKSOF|winfixer
RKSOF|WinFixer2005
RKSOF|WinFixer_2005
RKSOF|WinSoftware
UINST|UWFX5_is1
UINST|WFX5_is1
FILEN|%ALLUSERSPROFILE%\Start Menu\Programs\WinFixer 2005\WinFixer 2005.lnk
FILEN|%USERPROFILE%\desktop\WinFixer 2005.lnk
FILEN|%USERPROFILE%\desktop\WinFixerScannerInstall.exe
IEZON|.winfixer.com
FILEN|compcln.dll
FILEN|df_fixer.dll
FILEN|df_proxy.dll
FILEN|ffwraper.dll
FILEN|fixcore.dll
FILEN|mmfix.dll
FILEN|wfx5.exe
FILEN|winfixer2005trialsetup.exe
NEWPR|2796|Winhound Spyware Remover
PRCAT|43
CLSID|{0878f045-b52e-46b3-9724-d3ae69d50067}
CLSID|{0baca3c1-f734-4a5f-970a-15dbf7d3c09c}
CLSID|{0d4385df-f78a-4264-a32c-7dd4a72de539}
CLSID|{0ea04
667-e53b-4e81-8e7c-de2ca114cbd6}
CLSID|{19a0b5c9-65fe-4d3b-8bdd-efb7fe553c58}
CLSID|{19c99256-d011-47e2-bc64-6322096e20a5}
CLSID|{265c2af8-c94c-4aff-b2b6-340d3982562c}
CLSID|{2871b7af-2d4c-478f-be89-881881c272ab}
CLSID|{2b94cdfd-4a45-4b08-b105-54c709d07b28}
CLSID|{2c354a9b-a5df-41a3-bf40-2d72feac14d3}
CLSID|{2c797aa0-978c-4ac2-bbb4-f89d410b614e}
CLSID|{31e956bf-8ca9-4d75-b534-7ebc79770002}
CLSID|{3946a33d-bbc6-4792-a383-d855e0f76d91}
CLSID|{41d7bb0a-64e0-4ab2-bd0b-69ea78e462e8}
CLSID|{4aa55e8c-2c19-4f3a-91ec-43b6df937c4f}
CLSID|{4f93062d-7bda-48be-aeb6-88af2b1fe2d4}
CLSID|{5206df89-97fc-41ad-bae3-993e87053a99}
CLSID|{54007809-0689-4a40-9d8f-94c79d87d931}
CLSID|{557c3787-d066-496e-8caf-ba47da7365c1}
CLSID|{58e68548-42e2-479d-a9e0-86d9f2eaf02e}
CLSID|{5c083b7e-a083-4b20-a7ad-7c8e29085494}
CLSID|{5e5a79a6-c67b-444e-be58-bd0acefcda07}
CLSID|{649d371e-d3e3-4fc0-ac82-e91f73d8e79e}
CLSID|{655980f1-13d5-4da2-9e80-aa56c36876cb}
CLSID|{67196b3e-55a0-49de-ba11-66f07df804db}
CLSID|{6af126a9-b07a-4de4-883e-28d3eccd75d8}
CLSID|{6b436bdd-8b8b-4a1f-add5-e67b30c8f7dd}
CLSID|{6e9e448e-b195-4627-953c-5377fa9bba36}
CLSID|{7198f8da-012c-4db4-abd8-923a54c87900}
CLSID|{71bf80fd-7e91-4730-b6e8-8f3e81f5c38b}
CLSID|{81723c8c-918f-4456-b7e8-a68cf7a10c6d}
CLSID|{82847700-fe61-46a3-b3ee-761a1e312aca}
CLSID|{82a10659-a1e5-4732-a839-c910d955c88b}
CLSID|{84844b27-0d53-4c71-ab24-0151b33ab02f}
CLSID|{8c2a05c5-780f-4a2e-ae1c-fb8181f860e4}
CLSID|{8dca6b3d-1fca-4500-b210-76119bb5c69e}
CLSID|{a8bcf2b9-ed19-4637-ac77-bf59f131fa1f}
CLSID|{a9a73a66-b0e0-4ffb-828f-3a55e1fa4271}
CLSID|{acc647ee-991a-4811-b420-f063f50cddc1}
CLSID|{b6049d5d-718f-44c0-b965-06840d27e206}
CLSID|{b817d284-1b82-4793-b1f3-58a06dab03a1}
CLSID|{bc077dd0-42b5-451c-b78c-4ac97e4b116b}
CLSID|{c123dba0-52df-4272-bbaa-bfd092d07c2e}
CLSID|{c5b70256-5b08-4056-b84e-c6ce084967f5}
CLSID|{cb9dd914-68b6-4710-a04e-4745470706ce}
CLSID|{cbe4b748-08f9-44db-8fb1-9ad25979da35}
CLSID|{cdd964c2-fb78-4a74-bb1e-1cb1fcb72018}
CLSID|{d25f7446-4d36-4203-9ea5-5422b26fa9d0}
CLSID|{de1e317f-716a-4784-ba90-fda6d6a8fad5}
CLSID|{e12aaacf-8af2-4c31-ba94-e3787b44f90e}
CLSID|{e36dcdbc-57ad-4a1c-b9c6-1161441b51ca}
CLSID|{e479197f-49e5-4e60-9fa2-a71d4c7c2bbc}
CLSID|{e51ac62c-e82e-4e60-97ab-c66c4969af39}
CLSID|{ef5750b1-0aba-45c5-bf12-fb4d1d1150d2}
CLSID|{f1d9585e-20a6-4689-84c7-c19fe21c9a71}
CLSID|{f1e1a6b0-6cac-471b-99c4-4dbada883be8}
CLSID|{f880b4f2-75bf-44ec-b7aa-45ec37448027}
CLSID|{f8c9d1a9-b7b7-47ca-8b93-27c5b64d3a47}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\WinHound spyware remover
DIREC|%allusersprofile%\Start Menu\Programs\WinHound spyware remover\
DIREC|%programfiles%\WinHound\
DIREC|%userprofile%\Start Menu\Programs\WinHound spyware\
AUTST|WinHound
UINST|WinHound spyware remover
FILEN|%ALLUSERSPROFILE%\Desktop\WinHound spyware remover.lnk
FILEN|%ALLUSERSPROFILE%\Start Menu\Programs\WinHound spyware remover\Register WinHound spyware remover.lnk
FILEN|%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk
FILEN|%userprofile%\Desktop\WinHound spyware
FILEN|%userprofile%\Desktop\WinHound spyware remover
FILEN|%userprofile%\Desktop\WinHoundinstaller.exe
FILEN|%windir%\WinHoundInstaller.exe
FILEN|cwrapper.dll
FILEN|winhound.exe
NEWPR|2275|World Anti-Spy
PRCAT|43
DIREC|%AllUsersProfile%\Start Menu\Programs\WorldAntiSpy\
DIREC|%appdata%\skinux\worldantispy
DIREC|%programfiles%\worldantispy
RKSOF|WorldAntiSpy.com
UINST|WorldAntiSpy.com_is1
FILEN|worldantispy.exe
NEWPR|2599|X-Con Spyware Destroyer
PRCAT|43
DIREC|%programfiles%\X-Con Spyware Destroyer\
DIREC|%userprofile%\Start Menu\Programs\X-Con Spyware Destroyer\
UINST|X-Con Spyware Destroyer Beta 3.1.2
FILEN|%userprofile%\Desktop\X-Con Spyware Destroyer.lnk
NEWPR|2632|John The Ripper
PRCAT|44
NEWPR|3631|Pinch
PRCAT|44
FILEN|evcztdq_pinch.exe
FILEN|qmtsfzh_pinch.exe
]Nu1
ESPS
#t53
XJJJ
WD-b
M`XZ
WD-b
E3P3
|kernel32.dll
D$$%
8MZu
+K +
kernel32.dll
GetProcAddress
GetModuleHandleA
LoadLibraryA
user32.dll
advapi32.dll
oleaut32.dll
advapi32.dll
version.dll
gdi32.dll
user32.dll
oleaut32.dll
ole32.dll
oleaut32.dll
comctl32.dll
shell32.dll
wininet.dll
advapi32.dll
oleaut32.dll
GetKeyboardType
RegQueryValueExA
SysFreeString
RegSetValueExA
VerQueryValueA
UnrealizeObject
CreateWindowExA
SafeArrayPtrOfIndex
CoUninitialize
GetErrorInfo
ImageList_SetIconSize
ShellExecuteA
InternetSetOptionA
QueryServiceStatus
VariantChangeTypeEx
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
type="win32"
name="DelphiApplication"
version="1.0.0.0"
processorArchitecture="*"/>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
language="*"
processorArchitecture="*"/>
</dependentAssembly>
</dependency>
</assembly>
BWWb
RUrr
eXvvw
vE]]
E[[a
0UqqU
in5gX
Dr@9<
G4#0
$r 9`
CYT8
zX:;
jZ]_
w^$>u
@Dqe
UKSw
+dWS
G@IB
X,J|
!wtP
;R/?
t+b
E{&f
HK]0
$t ?
Y#m}
xla~{
a]Ri
LH+`
=DH$u,q
bm"p
5J<i
VF!H
Db(t
PRQ@.
#10t
A%R8
5hApb
-sZ
.#l8z
0lPj
YR@'
B) 90
SOFTW
\Borla>nd
FPUM
askV
`YPZR(
o0|_
?.Q[
ZTUW
@)10
,t\T
a/P(
0Kz&#
J;BWI
i:dhH
K|3D,5
ExH^
8 t>
7ubf
Porti
s COpy~
1983
Pa#EA
A~^*p
ThzB
Zs)i
0-Rf;
#;0c\
"XJ$
a8]@\(:
m.nB
PbV3
5q"#
f@8&
~ u&0
'|cp
%=z_
aOCM
xa/F?
\qfWcHy
9j[,/f`
/`A
RSu9
oftw
!WpA
%yB
?=%{
y0[!Hu
PE6^
2GZv
fRqK
Q(_*
XuIL$
TQ0Y
U@:?
BkU'
{@?v
)#VZ
-;,+#
^OA
q,/b<
<@N)
cD3
Vq-#
`nj4[xz
p?'u
CM`0
@|H<1
(r$9
-Pz_
GHIJK
OPQRST8UV
WXYZabcpd
efghijkl
nopqrst
wxyz01
5678
+/=
$()[
]{},;
\*"'
O?L%
g%IU
~n9v
R.f'u
$'x:
aWp[
mory
\qX8!
ternalA
9X^:
-,#lb
!lq\
EDivByZ
RangCe+
(`Pto
,BPrh
tack
DpHtk;lr
BN`@
2lS`
V~MD
\:@`
&6{A
;?(Q
^_qQ
q[c%`@4
L+<&
'R@%
r@<9
w7k{
&/<`R
&2nh`
K{c@
b-U@4
C`Y*X
AP"@
8fn<
6|H@
s'tz
C'<w~
np-w
AHSv
,PI2
zt{!?=
moswL
y*Os
<&j~
S0P*h
A\9@
.)s$
e0?@Yt
j$<DR
HpF
5Vj)
J7.Pj
(CBpw
H@GB
SpQy0Jz
FS#U
0GfI
IWEd
hZJ 9
8Jxy
f=)@
z`q,
*z~@
"(O4/
K6fC
J?!#
m/d)[q
AMP\)
@`l32.d
skFr
)pH_
#~(t
g4$|V
8zx@Pt
I9NF:A^\
QS]$f
.[Y9
$*@t
Li8^A
=Jti
<8't
D.51v9::;e
Y~mb`}e.
a)=D
Q1b0
J?,$
3n-
1Kc"
qm<p$
x>0U
5ES:
|vCj
BI<d
Mu'E
FhCH
,8p@
a8+~=
e%YZ
0JU,
(<.B
"J{dP
{(`[
@g~-{
#!En
=@{p
(3Hz
@R)j
yglAP
f8ZE
j'4F!
[e0X't
uCz8
sBxS<}M
5%<ZFr
2};uv
hBr-`|'
Bu5i
R #H[(
o!>N
j0Xu
;BN%
&}-F~U
*3Q,
^KV, !
ul($
mfC"
FV:"
o9@f
^zsf
QZ)^&
ogv@0
&d(N
D&")
+[eC
`}"F#
j ])
v]8]
:!4B
ZLBr:P
/H~|
.`;O
tb@\
Q(&Z>
kHgc
#L?(
<6!}
D(!*
{E#0
#u@&
T'kO
K>1Ig0.
oL`"
(X4S
P(1v0F
qYj3
O\jH
`$hX
<iFfe:Q`(y
j.dS
T$c
d_d,x
VTd`
l5dp>
=bK<
cTG(
2nHH$
$X?_
>}?p
$0[4&
=mI;F
Vf;@
Oper
!r3;<#
]v$FH
9Rf(
+!`II$
|y/K
AF-W
]V}L
ZN*W\SV
TJG2
tO_o
;KS*
Vt.vY
EM329
Untd8ql
nf|o
^Z[Y
Y_|h6u
VMT
<v,~T
@~y*2s
Hoqvtb
R?nd09
`iTZ
n~BHI
|i:X
.C"3
u<8l
rFgavc
wVs9
OH$Y
uC>Ta
0hKH
;?}S
0H~d
M8Jh
<j@'Ru
IK-N
YDa56
:iP=
SB"#@
'}W%_
8VL;i%
AZ@u~
SI`CA(
WV\D'
mq;t
4'T2
t+;G
EFou
:X:|
'S>#
o-Dq
&yLe
GM:
h('$
'g! !
}Buz
[^Y]
o+j#P
mAh@*
_Isns7u
-"5q,
P,BV
$m,'
^3Bd-
RX"U
$RSW
M_~Js
_[RZJ"
^RJ}
RsN^Lp
or-diT
~c=u;
n=t7b
LOAD
d/pC
nt]}
tx$L
!<><,
Ht[;
)u7S
"sW9
D:24
(f{B
^w@tD
"(Bf
%Yx`
D9_F
N!`(2
=lfp
9cU42Y
Ph%l?
]P+t
<ZC@
)^yXHu
${j7
a``<6
&\^r
ADAp
D;@V
,eFU
jEBp?
<~QY
cH_J
! |q
RQ@8
PQW#
C+j8
(08@
<rR'
@Ifk1
8 <~A
&Lb+
u|d
0!dv
ET~H
6Sej
`u(j
p$2FHq
AQHF
u]:q
PCRN
h%="
3\E5
<~e,@
`Pz4
S]WE
@GFP
MVCP[H
bugs@a
c9k.
1$68
rRtL
ch|R
=1"w
,)zp
{#?B
|W="L
w[_@
time
,"4D<#
erj8
"13t
t`> 1
$ 8\394\X
zd78L
h@WP
>,~L
1?L"
L3&,1/
4<9v
Xc|x<p
r=>
($:HJ
V"bEt
`"pD~L
<sn?
.d{P
3,on
ToMu
cpy6
ExA'
Unw>dE
mTsi
3Iu&
0{v)pi<J
ISd(
A)@5`<0
$hf%
43VL
pLDB&v
YArb
Z[gJ)c
oPw"D
3=5g{
Guipd
',G8o
B'JGRgZ
G9;g:
:9?C
<M=S>\?c
'$D;
2>N
5*:KH6<}
<b=w>
<RNp
c8D9<
4;?S
97l;:
48LN]
sI=N>
rJtsv
X~~N\
q&=H
d;l<p=t>x?|?
:($0,
p4>8v?
xJ:~~
<,J4
<X=\>`?d?t?
H:P;T<X=\
x~h@iMp
@9`0
;x<|=
z4|8
2p/0
P<0@
%j'f
Xtv`C
9V`Z
>rMHg
92Cz
yo<8
Sjtap
&?:P
$9):
5v=xRz
Z|wN
'$I
|$~p
fYp0:|,
Y2A$F
CZ;b
94S:X;
G`O$2e
xz%|+
t!v)x
9zG|
_'eGmgu
QfG\
PtAu
F'JGW`c
vXx~O
!;aZP
z$U|
ktzv
C?Ox
2T<9
6!:3|
0z,|
54@d
(7X?
$zM|`K
vox}
;Y%}
-hC\A
93c:
<EX6
v4x:zI|N
:A;L
<U/_
"E/O
~XT\
2?|%
tHML&
_x._
A ,$
6'P?
LPh&u
[^5YXbeH
0nQ)
_&j0
?5\A}
ldK+
W HI
=8:,
HW@X
f^s|
tKq?
PJ3W
C1M)ag
Bo8xA=w
printf
oJp>
|mlc. k
b#Mo
A'Lo
$DQp
G:h-
nle4
*{>=
tpXS
|2b3
9n#k
h[E*
?wyE
vq<b
&"[5;
j}\%A5
]f-F[
soP,j
FF3@
%wI_8f
co7d
C_p]
F.(x
vzxP
*_0)
2pRi!
&+P"xnX
Ekhf
0?N :
<B{@
=&0G
z+b:nZ
U}95
!TFL
- ]:
yN@$)T1Pe
E~v!
[8>+
[<&VSE
H,G{
RT>N
C*M#
ab6k
4=Nx$
!Q|U
LmY4
0st(
VBh9
:deI
w:"L
;r}/
bm(AWQ
PWJQ]Shm&
U+O({O
N?[q2
OB8L0~O
x<"r
r2Lf
(H_U
&^6H
%W~C
<hG-
0Rj@Q
N@K}
.Nv^
/ vX
i9vLJ
8QEgs
sv<0
UN=I(om
? l%
zLj"=$
rcb0%!
eNyd55R
-(RC
eFYq]f>cO
>kbN
vfGZ8
lJFVj
Dcn~
MJD`
]h8F
E-wP!
/fIX
lo=t
zlV&
|AaM
i;jC
cyn\
@bd?,
jH=Y
N%4tUi
>d#n
|~@=
d;,la
a>Bg
f1wY
_f=^
-F,X
ZcD@
$%zP
/a=?
f{&=O
#`4yt
X'!p
k.Bw_
o\&>^
C5*T$K
U860
xMR^YL
FKBJI
@ AZ
V={i
d:xY
#4Zo
H[.c
!gJr
Lw~ps
$suI
g/Q_
USQP0`
?#ZF
|FY<'
&)7oAhl
Rhee
(k$Sp
c87U
ARkw
viE#a
qe{.vV
cC5>
QGG*
4V"{
wLhg
F[}[
z],m
2OLL%
w`~uD*
wWB=
d-0*
/++<
tnON7
_cBb
;l|o
Up:8u
A KJ'
#[hB
f*6x8
W1y0
!/'
\u%iD,,
x> >
zp'0
EmfDJC
XY/>
u>c48
i;N#
rsIe
~|kTQ
L}nJ
c852
9YXx
o4GD
ojq"
5dU+
!ghT
3<Hrh
PUAY
_K,V4
,aCcL
Xw^yw
vriDsc
n"q-^a
p}_u2
zbd9
BBh{
)G4?-0rT
;pi+.
#=IY
[MdZD
"E\C
OH+*][
v"ZU
&wvN
-sc@2
^rYn
0zRPa
oY[3WlM
voOc
V(Qu
*Mc7!
#aQe7[
WKYF1
YU@=B
z9:g
d,X~
3J)c
, dc
NkHQ
4BTP
;/+\
-yAy
HU:=
??mz
]=JQ
T=obx$
4Tc-
k}^+&
[GuPT0y`
0VAL
'.p|Ls
tDWb
c,?]
g?m$
7Y<C
Lw*4
kT8\
Ixw`
-P$AE
m+n5G@s
v2(s?
tn=f
OF`:
;9}D
H%k8+
4AW%
JWJgY3
NKGD
'C?L
I(f)
@sY
r)vY
$vTd
=oE#
h@1B
_.gF
_8W:
H3TM
Unicode Strings:
---------------------------------------------------------------------------
jjjjj
jjjj
jjjjjj
B'B1B
jjjj
jjjj
jjjj
jjjj
jjjj
jjjj
jjjj
jjjj
ebutton
clock
combobox
edit
explorerbar
header
listview
menu
page
progress
rebar
scrollbar
spin
startpanel
status
taskband
taskbar
toolbar
tooltip
trackbar
traynotify
treeview
window
jjjjj
9-+,
jjjj
jjjjj
jjjjj
jjjj
jjjj
jjjj
jjjj
jjjjj
jjjj
jjjj
jjjjj
jjjjj
jjjjj
jjjjj
jjjj
jjjj
jjjj
jjjj
jjjjj
jjjjjjj
jjjjjjjj
jjjj
jjjj
jjjjjjj
jjjjj
jjjjj
jjjjjjjj
jjjjjjj
BBABORT
BBALL
BBCANCEL
BBCLOSE
BBHELP
BBIGNORE
BBNO
BBOK
BBRETRY
BBYES
CDROM
CLOSEDFOLDER
CURRENTFOLDER
EXECUTABLE
FLOPPY
HARD
KNOWNFILE
NETWORK
OPENFOLDER
PREVIEWGLYPH
UNKNOWNFILE
DLGTEMPLATE
DVCLAL
PACKAGEINFO
TFalertTEMPLATE
TFMAIN
TFRMalertSPYWARE
TFRMalertSPYWAREV2
XC_DEFS
MAINICON
MS Sans Serif
eWould you like to abort the removal? You can always continue the removal later on by scanning again.
Gator has been detected on your machine. While this is a known adware program, there is also a password management component included that you might be using. Would you like more information on migrating your data?{X-Cleaner needs to be updated!
Please use the update feature or visit http://www.xblock.com/ to receive the needed updates.(This program will stop functioning soon!
Scanning for %s...dThis spyware was installed with the password "%s".
Do you want to try run the configuration program?
Password Decoded!nProgram expiry has manually been disabled.
Your protection might not be up to date against the latest threats!
Continue with the removal?9This scanner should not be used on Ernst & Young systems.
LAn update is currently available.
Would you like to download and install it?
Update AvailableYHit OK when the UnInstaller has completed or when nothing happens during seve
al seconds.
Done?
Before removal
Create System Restore Point?
Removal of these programs can sometimes cause incompatiblities with other programs.
It is recommended to first make a "System Restore Point".
This enables you to "roll back" any changes later. Create it now?
Detected 'Repair failed. Please contact support.
Repair succesfully completed
Errors were detected during verification of your "Layered Service Provider" settings!
You might experience trouble using some Internet Application because of this.
Attempt repair now?
Always ignore this product?>Are you sure that you want to ignore and stop detecting "%s" ?
Scanning for %s ...cIt is recommended that you reboot your PC after the removal of software.
Do you want to reboot now?
Reboot?
@16KB instruction cache, 4-way set associative, 32 byte line size78KB data cache 2-way set associative, 32 byte line size916KB data cache, 4-way set associative, 32 byte line size
No L2 cache?Unified cache, 32 byte cache line, 4-way set associative, 128Kb?Unified cache, 32 byte cache line, 4-way set associative, 256Kb?Unified cache, 32 byte cache line, 4-way set associative, 512Kb=Unified cache, 32 byte cache line, 4-way set associative, 1Mb=Unified cache, 32 byte cache line, 4-way set associative, 2Mb
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Could not get Windows to reboot#Error getting permissions to reboot
(Dead)
Window Background
Window Frame
Window Text
No help keyword specified.
Your system clock does not match the current time. This can cause problems with some applications.
Please correct this immediately.ASorry, this program has expired.
Please download a new version.XThis program is about to expire.
You need to obtain a new version as soon as possible.
Expire Warning
Expired!
Warning
Error=Instruction TLB, 4Kb pages, 4-way set associative, 32 entries8Instruction TLB, 4Mb pages, fully associative, 2 entries6Data TLB, 4Kb pages, 4-way set associative, 64 entries5Data TLB, 4Mb pages, 4-way set associative, 8 entries?8KB instruction cache, 4-way set associative, 32 byte line size
Caption Text
Default
Gray Text
Highlight Background
Highlight Text
Inactive Border
Inactive Caption
Inactive Caption Text
Info Background
Info Text
Menu Background
Menu Text
None
Scroll Bar
3D Dark Shadow
3D Light
Blue
Fuchsia
Aqua
White
Money Green
Sky Blue
Cream
Medium Gray
Active Border
Active Caption
Application Workspace
Background
Button Face
Button Highlight
Button Shadow
Button Text
"Unable to find a Table of Contents
No help found for %s#No context-sensitive help installed$No topic-based help system installed
Black
Maroon
Green
Olive
Navy
Purple
Teal
Gray
Silver
Lime
Yellow
Right
Down
Shift+
Ctrl+
Alt+ Clipboard does not support Icons
Cannot open clipboard
Text exceeds memo capacity/Menu '%s' is already being used by another form
Docked control must have a name%Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
&Abort
&Retry
&Ignore
&All
N&o to All
Yes to &All
BkSp
Enter
Space
PgUp
PgDn
Home
Left
Abort
&All
Cannot drag a form
Metafiles
Enhanced Metafiles
Icons
Bitmaps
Warning
Error
Information
Confirm
&Yes
Cancel
&Help
"Cannot make a visible window modal
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active*A control cannot have itself as its parent
Cancel
&Yes
&Help
&Close
&Ignore
&Retry
Metafile is not valid!Cannot change the size of an icon
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Invalid ImageList Index)Failed to read ImageList data from stream(Failed to write ImageList data to stream$Error creating window device context
Error creating window class+Cannot focus a disabled or invisible window!Control '%s' has no parent window
Cannot hide an MDI Child Form)Cannot change Visible in OnShow or OnHide
List index out of bounds (%d)+Out of memory while expanding memory stream
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to create key %s
Failed to get dat
a for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Stream write error
Bitmap image is not valid
Icon image is not valid
*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid stream format$''%s'' is not a valid component name
Invalid property path
Invalid property value
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
January
February
March
April
June
July
August
September
October
November
December
Interface not supported
Exception in safecall method
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
A call to an OS function failed
Write$Error creating variant or safe array)Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction(Exception %s in module %s at %p.
%s%s
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Read
!'%s' is not a valid integer value
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow Invalid floating point operation
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
XBlock.com
FileDescription
X-Cleaner
FileVersion
1.1.1.11
InternalName
LegalCopyright
(C) 2003 by X-Block.com
LegalTrademarks
All rights reserved.
OriginalFilename
ProductName
ProductVersion
1.0.0.0
Comments
VarFileInfo
Translation
Size: 750616 Bytes
MD5: 09B550B74C729232F2C88A9B98AE4F0C
Packer: File not found C:\iDEFENSE\SysAnalyzer\peid.exe
File Properties: CompanyName XBlock.com
FileDescription X-Cleaner
FileVersion 1.1.1.11
InternalName InternalName
LegalCopyright (C) 2003 by X-Block.com
OriginalFilename OriginalFileName
ProductName ProductName
ProductVersion
Exploit Signatures:
---------------------------------------------------------------------------
Scanning for 19 signatures
Scan Complete: 1896Kb in 0.094 seconds
Urls
--------------------------------------------------
IEZON|http://*.systemdoctor.com
IEZON| http://www.winantivirus.com
IEZON| http://www.winantiviruspro.com
Please use the update feature or visit http://www.xblock.com/ to receive the needed updates.(This program will stop functioning soon!
RegKeys
--------------------------------------------------
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , *.system-processes
REGKE|HKEY_CURRENT_USER\Software\Maxthon\Plugin\toolbar\{44BE0690-5429-47f0-85BB-3FFD8020233E}
REGKE|HKEY_CURRENT_USER\Software\VoiceIP
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\webHancer Agent
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WUSE.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WUSN.1
NEWPR|2337|WhistleSoftware
DIREC|%ProgramFiles%\WhistleSoftware\
RKSOF|WhistleSoftware
UINST|Whistle Software
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WinA
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\pup
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\woualo
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Yazzle Snowball Wars
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yazzle Snowball Wars
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Yazzle Sudoku
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\YazzleSudokuGame
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , dns-look-up.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , netbios-wait.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , netsearchsoft.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.dns-look-up.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.netbios-wait.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.netsearchsoft.com
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ccaccess.dll
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Emitt
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform , ADVPLUGIN|K115|165|S-866237264|dialno
REGKE|HKEY_CURRENT_USER\Software\SiteIcons\Dialers
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pmxy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-pmxy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/comload.dll
REGKE|HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/unidist.ocx
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\PMT
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Ebates.
REGKE|HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\alertSpy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\alertSpy.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiVerminser.exe\
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusProtection.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Telecom Advance\Antivirus Protection
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusSolution.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\Ad-Protect.Addin.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ad-protect.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ContraVirus.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\ExpertAntivirus.Addin.1
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\AdLoader
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Trace7
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\1das\AdLoader
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\dnl7\tracer
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ExpertAntivirus.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\myCleanerPC
REGKE|HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\Pestbot
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Pestbot.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FindExtensions\Static\RegFreeze
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\Spy-Shield.Addin.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Spy-Shield.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\SpyAxe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\SpyAxe.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\spyaxe.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyDawn.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyFalcon.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHazard.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHeal.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Spyware Cleaner
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareQuake.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler , {E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Spyware-Secure
AUTST|Software Soft Stop
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareLocked 3.5.exe
REGKE|HKEY_CURRENT_USER\Software\VB and VBA Program Settings\VBouncer
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\virus-bursters.exe\
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\VirusProtectPro 3.4.exe 3.4
DIREC|%ProgramFiles%\Common Files\WinSoftware\
RKSOF|WinSoftware\WinAntiSpyware 2005\
DIREC|%allusersprofile%\Application Data\WinSoftware\WinAntiVirus 2005\
DIREC|%userprofile%\Application Data\WinSoftware\WinAntiVirus 2005\
RKSOF|winsoftware\winantivirus 2005
RKSOF|winsoftware\winantivirus 2005 trial
DIREC|%commonprogramfiles%\winsoftware\
RKSOF|WinSoftware
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\WinHound spyware remover
Scanning for %s ...cIt is recommended that you reboot your PC after the removal of software.
ExeRefs
--------------------------------------------------
FILEN|surfairys.exe
AUTST|cashplusmedia.exe
FILEN|ssk.exe
FILEN|ssk3repairinstall.exe
FILEN|ssk3_b5 seedcorn 4.exe
FILEN|surfsidekick.exe
FILEN|syncroad.exe
FILEN|tagasaurus.exe
FILEN|tagasuarus97.exe
FILEN|133_funtarget_4_0_4_0.exe
FILEN|tsinstall_4_0_3_8_b17.exe
FILEN|tsinstall_4_0_4_0_b4.exe
FILEN|%systemroot%syssfitb.exe
FILEN|tgdc.exe
FILEN|ucmoreiex.exe
RKSOF|Microsoft\Windows\CurrentVersion\App Paths\TinkoPal.exe
RKSOF|TinkoPal.exe
AUTST|Zstb.exe
FILEN|zsearch.exe
FILEN|zstb.exe
FILEN|winupie.exe
FILEN|trustinpopups.exe
FILEN|%windir%\tvm_b5.exe
AUTST|djtopr1150.exe
FILEN|unibar.exe
FILEN|vsolutions.exe
FILEN|bi_prob.exe
FILEN|sysvx.exe
FILEN|%userprofile%\desktop\WeatherscopeSetup.exe
FILEN|weatherscope.exe
FILEN|weatherscopesetup.exe
FILEN|whagent.exe
FILEN|whagent_update.exe
FILEN|whcc-giant.exe
FILEN|whcc_realeuser.exe
FILEN|whinstaller.exe
FILEN|whsurvey.exe
FILEN|edowst3.exe
FILEN|zcwedowst3.exe
FILEN|websecurealert.exe
FILEN|websecurealertsetup.exe
FILEN|websecureuninstaller.exe
FILEN|vvsni_sync_webinst.exe
FILEN|vvsn.exe
FILEN|whse_pb.min.g2inst.exe
FILEN|vvsn_fanz0110inst.exe
AUTST|WhenUStart.exe
FILEN|vvsni_pbtb0100inst.exe
FILEN|saveinstcm.exe
FILEN|saveuninst.exe
FILEN|saveupdate.exe
FILEN|setupsavenow.exe
FILEN|vvsni_savenowsiteinst.exe
FILEN|setupweathercast.exe
FILEN|weatherinst.exe
FILEN|weirdontheweb_topc.exe
FILEN|mediaaccess.exe
FILEN|mediaacck.exe
FILEN|winad.exe
FILEN|winka.exe
FILEN|msupdater.exe
FILEN|mynexus.exe
FILEN|webnexus.exe
FILEN|wnad-update.exe
FILEN|wnad.exe
FILEN|bobsaver.exe
FILEN|popunder.exe
FILEN|xtcfgloader.exe
FILEN|xtcfgrunner.exe
FILEN|xupiterstartup.exe
FILEN|xupiterstartup2003.exe
FILEN|xupitertoolbarinstaller.exe
FILEN|xupitertoolbarloader.exe
FILEN|xupiterwauninstaller.exe
FILEN|best.exe
FILEN|yazzle1119oinuninstaller.exe
FILEN|yazzle1264oinadmin.exe
FILEN|yazzle1264oinuninstaller.exe
FILEN|yazzlebundle-1264.exe
AUTST|FT_SilentSudokuInstaller.exe
FILEN|ageu_silentsudokuinstaller.exe
FILEN|ageu_sudokuinstaller.exe
FILEN|ft_silentsudokuinstaller.exe
FILEN|gs_silentsudokuinstaller.exe
FILEN|yazzle1119oinadmin.exe
FILEN|yazzlebundle-1119.exe
FILEN|yazzlebundle-1304.exe
FILEN|yazzlebundle-1438.exe
FILEN|yazzlebundle-1452.exe
FILEN|waterfalls1awfree.exe
FILEN|yourscreen_4_pch.exe
FILEN|yoursitebar.exe
FILEN|adstartup.exe
FILEN|%programfiles%\zango\zango.exe
FILEN|zango.exe
FILEN|zangoinstaller.exe
FILEN|zangomuncher.exe
FILEN|zangotbuninstaller.exe
FILEN|jadeshadowinstall.exe
FILEN|jadeshadowsetup.exe
FILEN|zapspot.exe
FILEN|dwdsregt.exe
FILEN|zicorn001.exe
FILEN|icont.exe
FILEN|%windir%\system32\spiven.exe
FILEN|zipclix.exe
FILEN|axdlplug-1.5.0.0-0281-setup.exe
FILEN|axdlplug-1.5.0.0-147-setup.exe
FILEN|npdlplug-1.5.0.0-147-setup.exe
FILEN|%systemdrive%\msole32.exe
FILEN|opensite.exe
FILEN|absolu-trans.exe
REGKE|HKEY_CLASSES_ROOT\AppID\exengd.EXE
FILEN|int179663.exe
FILEN|gdnus208.exe
AUTST|addot.exe
FILEN|adult_chat.exe
FILEN|tibs3.exe
FILEN|dbn1742.exe
FILEN|%Windir%\system32\dsldbaccess.exe
FILEN|%Windir%\system32\Geaccess.exe
FILEN|2da45.exe
FILEN|beauty[schoenerwerden,1].exe
FILEN|cocktails[ccp-10097,de].exe
FILEN|gifsworld[gwd-10927,de].exe
FILEN|hausaufgaben[hun-10002,de].exe
FILEN|hausaufgaben[hun-10222,de].exe
FILEN|horoskop_erstellen[aie-10070,de].exe
FILEN|lehrstellen[lhs-10004,de].exe
FILEN|liebesbriefe[lbi-10023,de,start].exe
FILEN|pflanzen[pla-10006,de].exe
FILEN|routenplanerag.exe
FILEN|sagen.exe
FILEN|satanismus.exe
FILEN|satfrequenzen.exe
FILEN|scheisse[schei1,1].exe
FILEN|schulstadt-1.exe
FILEN|schulstadt-2.exe
FILEN|schulstadt-3.exe
FILEN|schulstadt-4.exe
FILEN|schulstadt-5.exe
FILEN|schulstadt-6.exe
FILEN|schulstadt-7.exe
FILEN|schulstadt.exe
FILEN|schwanger.exe
FILEN|setup(1-1md-0-0-,us)-1.exe
FILEN|sexworld[sexworld,1].exe
FILEN|sharing-ag-1.exe
FILEN|sharing-ag.exe
FILEN|slowenien.de.exe
FILEN|smiley[smileycastle,1].exe
FILEN|smiley[syc-10008,1].exe
FILEN|smilie-fabrik.exe
FILEN|sms-stadt-1.exe
FILEN|sms-stadt-2.exe
FILEN|sms-stadt-3.exe
FILEN|sms-stadt.exe
FILEN|sms-tool.exe
FILEN|songtexte[sgx-10001,1].exe
FILEN|songtextzone-1.exe
FILEN|songtextzone-2.exe
FILEN|songtextzone-4.exe
FILEN|spass4u[s4e-10020,1].exe
FILEN|spasspilot-1.exe
FILEN|spicktricks[ree-10323,de].exe
FILEN|spieledownload[ssg-10001,1,a63e].exe
FILEN|spieleindex[spieleindex,1].exe
FILEN|spiele_runterladen[geg-10066,1].exe
FILEN|sprueche.exe
FILEN|stammbaum.de.exe
FILEN|starfuck.exe
FILEN|stars-nackt.exe
FILEN|sternzeichen[szn-10011,de].exe
FILEN|straflos[anti-report,1].exe
FILEN|suchmaschinen-1.exe
FILEN|supergames[supergames,1].exe
FILEN|taroskop.exe
FILEN|tattoo-1.exe
FILEN|tattoo-2.exe
FILEN|tattoopalace-11.exe
FILEN|tattoos[tod-10109,de].exe
FILEN|tattoos[tod-10133,1].exe
FILEN|tattoovorlagen-de[toe-10362,1]-2.exe
FILEN|tattoo[tattoomania,1].exe
FILEN|tattoo[toe-10082,1].exe
FILEN|template-tempel.exe
FILEN|tests[iqwelt,1].exe
FILEN|test[teh-10116,de,start4].exe
FILEN|tierbabys[tierbabys,1].exe
FILEN|toprezept.exe
FILEN|trilian[trilian-de,1].exe
FILEN|tuerkei.exe
FILEN|turkgays[tks-10001,1].exe
FILEN|umsatzsteigern[uee-10001,1].exe
FILEN|valueradio-1.exe
FILEN|vornamen.exe
FILEN|vornamen[vnf-10049,1].exe
FILEN|vornamen[vnf-10103,1].exe
FILEN|wetter-basis-1.exe
FILEN|wetter-basis.exe
FILEN|witzealarm.exe
FILEN|witze[counterde,1].exe
FILEN|wohnung.exe
FILEN|maxd641.exe
FILEN|syslcznp.exe
AUTST|ciakaisen.exe
AUTST|lateshow.exe
AUTST|wke.exe
FILEN|%USERPROFILE%\Start Menu\messaggio3.exe
AUTST|sws.exe
FILEN|gd-ff_be.exe
FILEN|gd-ff_us.exe
FILEN|gdnca167.exe
FILEN|hacker spider.exe
FILEN|123-sexkino.exe
FILEN|aktgirls.exe
FILEN|aktshow.exe
FILEN|amateur-hardcore-sex.exe
FILEN|analorgasmus.exe
FILEN|analxxx.exe
FILEN|babesex.exe
FILEN|begleitung-online.exe
FILEN|berlin-erotik.exe
FILEN|betnaker.exe
FILEN|bigbusen.exe
FILEN|bumsmich.exe
FILEN|bundesligagirls.exe
FILEN|busencam.exe
FILEN|busenline.exe
FILEN|busenshow.exe
FILEN|busentreff.exe
FILEN|busenweb.exe
FILEN|camcontrol.exe
FILEN|casarossa.exe
FILEN|city-girls.exe
FILEN|clickfick.exe
FILEN|computersex.exe
FILEN|cyber-angels.exe
FILEN|cybererotiva.exe
FILEN|debabes.exe
FILEN|degirls.exe
FILEN|deutsch.exe
FILEN|devotelust.exe
FILEN|disnex.exe
FILEN|donnavargas.exe
FILEN|dream-sex.exe
FILEN|e-kontakte.exe
FILEN|ecsfun.exe
FILEN|ero-world.exe
FILEN|eroclick.exe
FILEN|eroklick.exe
FILEN|erophone.exe
FILEN|eroplanet.exe
FILEN|erotic-news.exe
FILEN|eroticenter.exe
FILEN|eroticliveshow.exe
FILEN|erotik-news.exe
FILEN|euromodels2.exe
FILEN|fickclick.exe
FILEN|fickenonline.exe
FILEN|fickklick.exe
FILEN|fickline.exe
FILEN|fickschule.exe
FILEN|ficksie.exe
FILEN|fussballgirls.exe
FILEN|germany.exe
FILEN|gina-wild-sex.exe
FILEN|girls.exe
FILEN|girlsbesuch.exe
FILEN|girlshotel.exe
FILEN|girlstalk.exe
FILEN|glas-haus.exe
FILEN|hardcore-live-sex.exe
FILEN|hooters.exe
FILEN|hotbunny.exe
FILEN|hotelbesuch.exe
FILEN|hotelgirls.exe
FILEN|hotpower.exe
FILEN|hotvot.exe
FILEN|hotwied.exe
FILEN|klickfick.exe
FILEN|kontaktechat.exe
FILEN|lesbenhaus.exe
FILEN|life-girl.exe
FILEN|lifegirl.exe
FILEN|live-studio.exe
FILEN|livechatcam.exe
FILEN|livephone.exe
FILEN|livesex.exe
FILEN|livesexkanal.exe
FILEN|liveshow.exe
FILEN|lovephone.exe
FILEN|lucky-punch.exe
FILEN|macronedia.exe
FILEN|maxxcafe.exe
FILEN|meetboys.exe
FILEN|meinecam.exe
FILEN|moesenhaus.exe
FILEN|mytits.exe
FILEN|nacktshow.exe
FILEN|nudeliveshow.exe
FILEN|online-begleitung.exe
FILEN|online-escort.exe
FILEN|orgasmusbilder.exe
FILEN|orgasmusline.exe
FILEN|orgasmuslive.exe
FILEN|orgasmusparty.exe
FILEN|orgasmusvideo.exe
FILEN|osnastrip.exe
FILEN|pagesex.exe
FILEN|pam.exe
FILEN|peep-show-girls.exe
FILEN|persiankitti.exe
FILEN|persianklitty.exe
FILEN|phonegirl.exe
FILEN|phythom.exe
FILEN|playboobs.exe
FILEN|playgal.exe
FILEN|playmoesen.exe
FILEN|playmuschi.exe
FILEN|porncam.exe
FILEN|porno-porno-sex-sex.exe
FILEN|pornodelux.exe
FILEN|pornomoesen.exe
FILEN|privatbesuch.exe
FILEN|pussygeil.exe
FILEN|pussyhaus.exe
FILEN|redlightgirls.exe
FILEN|rotlichtchat.exe
FILEN|rotlichtgirls.exe
FILEN|rotlichtline.exe
FILEN|rotlichtshow.exe
FILEN|schulsex.exe
FILEN|sex-erotik-show.exe
FILEN|sex-live-chat.exe
FILEN|sex-porno-show.exe
FILEN|sex-rooms.exe
FILEN|sex-sex-porno-porno.exe
FILEN|sex-sex-sex-pussy.exe
FILEN|sex-tabulos.exe
FILEN|sexcall.exe
FILEN|sexdominanz.exe
FILEN|sexevents.exe
FILEN|sexfetish.exe
FILEN|sexillusion.exe
FILEN|sexkarussell.exe
FILEN|sexkeller.exe
FILEN|sexme.exe
FILEN|sexmich.exe
FILEN|sexpicturegallery.exe
FILEN|sexroulette.exe
FILEN|sexschule.exe
FILEN|sextacy.exe
FILEN|sexycamera.exe
FILEN|smutlamd.exe
FILEN|soos.exe
FILEN|strapsshow.exe
FILEN|strichgirls.exe
FILEN|strip-eonline.exe
FILEN|strip-girls.exe
FILEN|stripcan.exe
FILEN|striplime.exe
FILEN|stripline.exe
FILEN|strippenonline.exe
FILEN|stripschule.exe
FILEN|studiosex.exe
FILEN|suendenspiele.exe
FILEN|teenmail.exe
FILEN|telestrip.exe
FILEN|the-sweets.exe
FILEN|tittengeil.exe
FILEN|tittenline.exe
FILEN|tittenseite.exe
FILEN|tittenspiele.exe
FILEN|tittenweb.exe
FILEN|tittenwelt.exe
FILEN|travelsex24.exe
FILEN|venusgirls.exe
FILEN|venusphone.exe
FILEN|victoriasecreet.exe
FILEN|videochatcam.exe
FILEN|viona.exe
FILEN|vollbusicam.exe
FILEN|wichsen.exe
FILEN|wild-sex.exe
FILEN|xxxphone.exe
FILEN|hotactiondating-uninstall.exe
FILEN|hotactiondating.exe
FILEN|nsi145.exe
FILEN|gratis-sex-crack.exe
FILEN|traumdate.exe
FILEN|iedisco.exe
FILEN|view_sex_now.exe
FILEN|net900.exe
FILEN|od-dflt0001.exe
FILEN|od-stnd191.exe
FILEN|%systemroot%\Orgasm.exe
FILEN|30500105.exe
FILEN|parisvoyeur.exe
FILEN|browser_plugin.exe
FILEN|hotsurprise_be.exe
FILEN|ukvideo2.exe
AUTST|bodr.exe
FILEN|britney spears nackt.exe
FILEN|hzs-10030.exe
FILEN|stripsetup.exe
FILEN|systemvxd.exe
FILEN|clbmn2.exe
FILEN|tibsloader.exe
FILEN|adult.exe
FILEN|cammaus.exe
FILEN|deutsche-peepshow.exe
FILEN|erotik-hotel.exe
FILEN|funland.exe
FILEN|lustmaus.exe
FILEN|megabusen.exe
FILEN|nutte.exe
FILEN|sabine.exe
FILEN|sabine2.exe
FILEN|sexstop.exe
FILEN|spanner.exe
FILEN|stchat.exe
FILEN|telefun.exe
FILEN|tscash.exe
FILEN|ueber40de.exe
FILEN|xxxlivesex.exe
FILEN|23aw0001.exe
FILEN|arr.exe
FILEN|belgium_sex-uninstall.exe
FILEN|crush.exe
FILEN|datemakerintl.exe
FILEN|direktsex.exe
FILEN|freesexx.exe
FILEN|go in.exe
FILEN|handy-paradies.exe
FILEN|hardcoreteens.exe
FILEN|hotsex.exe
FILEN|hotsexvideos.exe
FILEN|hot_canada.exe
FILEN|lolitasex.exe
FILEN|od-stnd24.exe
FILEN|piratos.exe
FILEN|pissing.avi.exe
FILEN|sexy-uninstall.exe
FILEN|sexy_belgium-uninstall.exe
AUTST|\windows\syswin.exe
FILEN|agrit.exe
FILEN|alberghi.exe
FILEN|qualsiasi.exe
FILEN|xxlav003.exe
FILEN|xdiver.exe
FILEN|xgenius.exe
FILEN|almaster.exe-34cdc7f0.pf
FILEN|backdoor.hacktack.110.exe
FILEN|backdoor.hacktack.112.exe
FILEN|backdoor.hacktack.120.b.exe
FILEN|backdoor.hacktack.exe
AUTST|djebmm350.exe
FILEN|disp350.exe
FILEN|ebatesmoemoneymaker.exe
FILEN|ebatesmoemoneymaker1.exe
FILEN|websavingsfromebates.exe
FILEN|websavingsfromebates0.exe
FILEN|disp1150.exe
FILEN|sahagent-seedcorn1002.exe
FILEN|w11150.exe
FILEN|webrebates.exe
FILEN|webrebates0.exe
FILEN|webrebates1.exe
FILEN|webrebates2.exe
FILEN|webrebatesrun.exe
FILEN|webrebates_auto_installsilent.exe
FILEN|alexainstaller.exe
FILEN|mksc.exe
FILEN|ossproxy.exe
FILEN|rlvknlg.exe
FILEN|nhupdater.exe
FILEN|http-tunnelclient.exe
FILEN|httptunnelinstallerv403065.exe
AUTST|AdArmor.exe Monitor
FILEN|adarmor.exe
FILEN|adarmorinstaller.exe
FILEN|adarmor_monitor.exe
FILEN|adarmor_updater.exe
FILEN|ads adware remover.exe
FILEN|adsremover.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\alertSpy.exe
FILEN|alertspy.exe
FILEN|alfacleaner.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiVerminser.exe\
FILEN|antiverminser.exe
FILEN|av_setup.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusProtection.exe
FILEN|antivirusprotection.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusSolution.exe
FILEN|antivirussolution.exe
FILEN|antivirus_solution_setup_1.0.0.exe
FILEN|bravesentry.exe
FILEN|bravesentrysetup.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ad-protect.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ContraVirus.exe
FILEN|%temp%\ContraVirus 2.0 Installer.exe
FILEN|contravirus.exe
FILEN|contraviruspro.exe
FILEN|cv_1_setup.exe
FILEN|xpuupdate.exe
FILEN|%allusersprofile%\Start Menu\Programs\Startup\Start CurePCSolution.exe.lnk
FILEN|curepcsolution.exe
FILEN|udc2006.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ExpertAntivirus.exe
CLASS|ad-protect.EXE
FILEN|expertantivirus.exe
AUTST|FixerAntispy.exe Monitor
FILEN|fixerantispy.exe
FILEN|fixerantispyinstaller.exe
FILEN|fixerantispy_monitor.exe
FILEN|fixerantispy_updater.exe
FILEN|killandclean.exe
FILEN|killandcleansetup.exe
FILEN|killandcleanupdate.exe
FILEN|malwarestopper.exe
FILEN|malwarestoppersetup.exe
FILEN|isec30.exe
FILEN|perfectcleaner.exe
FILEN|perfectcleaner_setup.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Pestbot.exe
FILEN|pestbot.exe
FILEN|pestcapture.exe
FILEN|pestcapturesetup.exe
FILEN|regfreeze.exe
REGKE|HKEY_CLASSES_ROOT\AppID\ad-protect.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Spy-Shield.exe
FILEN|spyaway.exe
FILEN|spyaway_setup.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\SpyAxe.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\spyaxe.exe
FILEN|spycrush.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyDawn.exe
FILEN|spydawn.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyFalcon.exe
FILEN|atmclk.exe
FILEN|spyfalcon.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHazard.exe
FILEN|spyhazard.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHeal.exe
FILEN|spymarshal.exe
FILEN|spysoldier.exe
FILEN|spysoldier_setup.exe
FILEN|spyvampire.exe
FILEN|spyvampire_1.0.1.311_install.exe
FILEN|%userprofile%\Desktop\SCFree.exe
FILEN|%userprofile%\SCFree.exe
FILEN|spyclean.exe
FILEN|spywinclean.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareQuake.exe
FILEN|%WINDir%\system32\atmclk.exe
FILEN|%WINDir%\system32\dcomcfg.exe
FILEN|spy-quake2.exe
FILEN|%temp%\NSIS_SpywareSecure_trial_setup.exe
FILEN|spyware-secure_trial.exe
FILEN|spywaresecure_trial_setup.exe
FILEN|slimshieldinstall.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareLocked 3.5.exe
FILEN|spywarelocked 3.5.exe
FILEN|spywarelocked.exe
FILEN|spysheriff.exe
FILEN|spywarestrike.exe
FILEN|ss_setup.exe
FILEN|%windir%\SGPro.exe
FILEN|sgpro.exe
FILEN|sg_free.exe
FILEN|%windir%\downloaded program files\usdr6_0001_d08m0404netinstaller.exe
FILEN|sd2006.exe
FILEN|systemdoctor2006freeinstall.exe
FILEN|systemdoctorfreesetup.exe
AUTST|a856cdb1.exe
FILEN|bundleouter2601031121.exe
FILEN|vb2uninstaller4_19.exe
FILEN|vbouncerinner.exe
FILEN|vbouncerinner1007.exe
FILEN|vbouncerinner1106.exe
FILEN|vbouncerinner1107.exe
FILEN|vbouncerinner1108.exe
FILEN|vbouncerinner1109.exe
FILEN|vbouncerouter1123030429.exe
FILEN|vbouncerouter1203.exe
FILEN|virtualbouncer.exe
FILEN|virtual_bouncer.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\virus-bursters.exe\
FILEN|vb_distrib.exe
FILEN|virus-bursters.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\VirusProtectPro 3.4.exe 3.4
FILEN|VirusProtectPro 3.4.exe
AUTST|hclean32.exe
FILEN|wareoutupdate.exe
AUTST|fat.exe
FILEN|%USERPROFILE%\desktop\WinFixerScannerInstall.exe
FILEN|wfx5.exe
FILEN|winfixer2005trialsetup.exe
FILEN|%userprofile%\Desktop\WinHoundinstaller.exe
FILEN|%windir%\WinHoundInstaller.exe
FILEN|winhound.exe
FILEN|worldantispy.exe
FILEN|evcztdq_pinch.exe
FILEN|qmtsfzh_pinch.exe
Raw Strings:
--------------------------------------------------
FILEN|surfairypp.dll
FILEN|surfairys.exe
NEWPR|1128|SurfSideKick
PRCAT|5
CLSID|{000ab005-ff12-42c2-8df5-39e12e5f9c91}
CLSID|{02ee5b04-f144-47bb-83fb-a60bd91b74a9}
CLSID|{4a2283c2-4d10-4954-1bbc-b730a621813c}
CLSID|{ca0e28fa-1afd-4c21-a8dc-70eb5be2f076}
CLSID|{fa89e1b0-e902-6968-bea5-156ab2fc177b}
DIREC|%CommonProgramFiles%\vcclient\
DIREC|%ProgramFiles%\SurfSideKick 2\
DIREC|%ProgramFiles%\SurfSideKick 3\
DIREC|%programfiles%\SurfSideKick\
AUTST|cashplusmedia.exe
AUTST|cyshgd
AUTST|dB2qRTc5T
AUTST|DNS
AUTST|Ebwh
AUTST|ezisde
AUTST|GsAds
AUTST|kpfbph
AUTST|KwtFRTc2W
AUTST|lfecqh
AUTST|lqxcx
AUTST|MedGS
AUTST|mqwf
AUTST|mtzfcv
AUTST|opr
AUTST|pstdae
AUTST|qppxjf
AUTST|Qwnoyep
AUTST|SurfSideKick
AUTST|SurfSideKick 2
AUTST|SurfSideKick 3
AUTST|Windows Incontext
AUTST|xeqdnc
RKSOF|SurfSideKick
RKSOF|SurfSideKick2
RKSOF|SurfSideKick3
UINST|Surf SideKick
UINST|Surf Sidekick_is1
FILEN|repairs303169536.dll
FILEN|repairs303169590.dll
FILEN|ssk.exe
FILEN|ssk3repairinstall.exe
FILEN|ssk3_b5 seedcorn 4.exe
FILEN|sskbho.dll
FILEN|sskcore.dll
FILEN|sskcwrd.dll
FILEN|sskffcore.dll
FILEN|sskknwrd.dll
FILEN|sskuknwrd.dll
FILEN|surfsidekick.exe
NEWPR|2487|SweetBar
PRCAT|5
CLSID|{21ba3ee1-ccc9-4381-9997-928127b0c2d6}
CLSID|{68a7f9fa-a202-4d45-aaba-a10dcac0d899}
DIREC|%AllUsersProfile%\Start Menu\Programs\SweetBox\
DIREC|%ProgramFiles%\SweetBox\
AUTST|SweetBox
CLASS|SweetBox.SweetActive
RKSOF|SweetBar
SERVK|IPRIP
NEWPR|1697|SwimSuitNetwork
PRCAT|5
AUTST|swimsuitnetwork
NEWPR|979|SyncroAd
PRCAT|5
DIREC|%programfiles%\Windows SyncroAd
AUTST|Windows SyncroAd
UINST|Windows SyncroAd
FILEN|%SystemRoot%\System32\ide21201.vxd
FILEN|syncroad.exe
NEWPR|730|Syscpy
PRCAT|5
NEWPR|2465|System Process
PRCAT|5
CLSID|{2588bbaa-f6c6-0053-c746-05ce98d3d296}
CLSID|{465f66ce-d075-cca7-7426-098c0e74be6d}
CLSID|{49ae83eb-5b19-7104-6a65-0b52de3de139}
CLSID|{5064a992-9575-e73c-c514-0a4cb0eb764c}
CLSID|{688b592e-4ab8-49a6-f9b2-02b3db5f7b0a}
CLSIA|{9bb5b49c-0d59-418d-a6a5-f6373b8fef64}
CLSID|{c2eeb4fa-b6d6-41b9-9cfa-aba87f862bcb}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , *.system-processes
DIREC|%ProgramFiles%\BHO Plugin\
RKSOF|BHO
RKSOF|BHO\icons
RKSOF|System Process
UINST|Startup
SERVK|TCP and UDP Support
NEWPR|1168|System Soap Pro
PRCAT|5
AUTST|%ProgramFiles%\System Soap Pro
AUTST|System Soap Pro
RKSOF|system soap
UINST|System Soap Pro 3.2-AC1
NEWPR|1813|System61
PRCAT|5
CLSID|{c7967580-5f17-11d4-aac2-0000b4936e0c}
NEWPR|2785|TagAsaurus
PRCAT|5
DIREC|%programfiles%\Tagasaurus\
AUTST|TagASaurus
AUTST|win32094-86623726
FILEN|tagasaurus.exe
FILEN|tagasuarus97.exe
NEWPR|1914|TargetSavers
PRCAT|5
DIREC|%CommonProgramFiles%\ffor\
DIREC|%CommonProgramFiles%\tsa\
DIREC|%windir%\ffor\
AUTST|ffor
RKSOF|ffor
RKSOF|fqmq
RKSOF|mrqf
RKSOF|TSA
UINST|TSA
UINST|TSAUNINST
UINST|TSL Installer
FILEN|133_funtarget_4_0_4_0.exe
FILEN|tsinstall_4_0_3_8_b17.exe
FILEN|tsinstall_4_0_4_0_b4.exe
NEWPR|1701|Tatss
PRCAT|5
NEWPR|627|Tellafriend
PRCAT|5
CLSID|{5297e905-1dfb-4a9c-9871-a4f95fd58945}
CLSIA|{72a58725-2635-4725-8c53-676dfd1feb8d}
CLSID|{95b92d92-8b7d-4a19-a3f1-43113b4dbcaf}
RKSOF|zeropopup
FILEN|zp.cab
NEWPR|1703|TestTimer
PRCAT|5
FILEN|%systemroot%syssfitb.exe
NEWPR|424|TGDC
PRCAT|5
CLSIA|{05bbb56a-2a69-4a5c-bfda-43295dd67434}
AUTST|TGDC IE Plugin
FILEN|tgdc.exe
NEWPR|776|The Search Accelerator
PRCAT|5
CLSID|{3131a8d2-d92c-48ba-96ac-8a77d6a1d573}
CLSID|{33740aeb-2856-4004-b84b-37e2c0d4f13d}
CLSID|{44be0690-5429-47f0-85bb-3ffd8020233e}
CLSIA|{53cbee82-d747-11d3-9ed0-005004189684}
CLSIA|{607df741-7d0a-11d4-9edc-005004189684}
CLSID|{aae89d95-75cc-4708-87e5-60cf917b7b5b}
CLSIA|{ed8db0fd-d8f4-4b2c-bb5b-9ef040fe104d}
REGKE|HKEY_CURRENT_USER\Software\Maxthon\Plugin\toolbar\{44BE0690-5429-47f0-85BB-3FFD8020233E}
DIREC|%ProgramFiles%\TheSearchAccelerator\
DIREC|%programfiles%\UCmore\
DIREC|%userprofile%\Start Menu\Programs\UCmore - The Search Accelerator\
RKSOF|Effective-i
RKSOF|ucmore
RKSOF|UCmore.UcmoreTsaApp
UINST|UCmore - The Search Accelerator
FILEN|ucmie.dll
FILEN|ucmoreiex.exe
FILEN|ucmtsaie.dll
NEWPR|3046|Themexp
PRCAT|5
UINST|Themexp.org File
NEWPR|3161|Think-Adz
PRCAT|5
UINST|Enhanced Ads by Think-Adz
UINST|Think-Adz Search Assistant
NEWPR|2232|TinkoPal
PRCAT|5
DIREC|%ProgramFiles%\TinkoPal
DIREC|%USERPROFILE%\Start Menu\Programs\TinkoPal
RKSOF|Microsoft\Windows\CurrentVersion\App Paths\TinkoPal.exe
RKSOF|TinkoPal.exe
UINST|TinkoPal
FILEN|%USERPROFILE%\Desktop\TinkoPal.lnk
NEWPR|496|TinyBar
PRCAT|5
CLSIA|{69555be2-9a78-11d2-ba91-00600827878d}
CLSIA|{82599e0a-8c81-11d7-9f97-0050fc5441cb}
CLSIA|{8fb0f3e2-5193-11d7-9f88-0050fc5441cb}
NEWPR|2235|ToolBar.SBSoft.h
PRCAT|5
CLSIA|{bf8e8df4-fae4-4df4-acc0-d25ec1010714}
CLASS|TORUTORUX.ToruToruXCtrl
NEWPR|681|ToolbarCC
PRCAT|5
CLSIA|{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffa2}
CLSIA|{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffa6}
CLSIA|{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffa7}
CLSIA|{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffa8}
NEWPR|1258|ToonComics
PRCAT|5
AUTST|fqdin
AUTST|iedll
NEWPR|2516|Top20results
PRCAT|5
NEWPR|2645|Topfive searchAssistant
PRCAT|5
DIREC|%ProgramFiles%\TopSearch\
AUTST|TopSearch
RKSOF|TopMoxie\TopSearch
UINST|TopSearch
NEWPR|613|TOPicks
PRCAT|5
CLSID|{02cdb0ed-874a-4dcb-8d9f-c2e3b169f265}
CLSIA|{0352960f-47be-11d5-ab93-00d0b760b4eb}
CLSID|{16097036-894c-4c00-a61f-93ca0d49a70e}
CLSIA|{1717a4a5-d63a-4f70-b373-ae4aa46d1236}
CLSID|{1b540d44-3f61-4394-ae30-25fdc3649405}
CLSID|{1d3bce37-7834-4579-8169-e67681420a98}
CLSID|{258a3625-183b-4477-aee2-ea54df6d878d}
CLSID|{29e825aa-13bc-457c-806a-d72e4a25b3c5}
CLSID|{2ed5af98-9258-45ba-b79b-06625c92f662}
CLSID|{5c40012e-44ca-11d7-8411-0002a5f9d08e}
CLSID|{700dc0dd-f409-42e0-9de5-21ee1a2ba9fd}
CLSID|{80e81a0e-9741-4fbc-8ee3-3b78c04ada1d}
CLSID|{91d91d21-8008-429d-821c-7266aac84a9f}
CLSID|{9a7cfeda-5911-4ef1-b49a-35c34230ffc1}
CLSID|{9bbcf06c-dcd7-495d-80df-cdd5399d0ff8}
CLSID|{9d4548ce-92fd-4c6c-ae7f-3dbe3bc763d8}
CLSID|{9f8ac164-6826-4b52-8f65-9c31305e81cc}
CLSID|{ad5bc1f0-72d8-44b3-8e3d-8e8fecce43fb}
CLSID|{be7613d4-7d09-4cf8-b747-6dff0564891e}
CLSID|{ce9b37ec-d243-47a2-83db-3a8350175193}
CLSID|{d273d427-57c6-4b12-860f-bbb8195f6e2a}
CLSID|{d7cb5baf-18d9-46d4-8f72-909d409506fa}
CLSID|{e79dadc6-18d0-4a2a-831f-d196d41f8438}
CLSID|{fd42f6d3-7ab1-470c-979b-7996edc99099}
AUTST|topicks starter
CLASS|HtCheck2.CheckPage
CLASS|HtChe
ck2.CHelpObj
CLASS|IdiumUpdater.IdiumSysUpdater
CLASS|ToPicksReg.ToPickReg1
NEWPR|1806|TopSurfer
PRCAT|5
CLSID|{af657644-964c-4348-a8ad-72524b3a3ff1}
NEWPR|763|TotalVelocity zSearch
PRCAT|5
CLSID|{5886a6dc-aaf4-45e9-979a-8e5e6dee30e7}
CLSIA|{828a9ed2-c5bb-4caa-bcb7-a4cc024aafd6}
DIREC|%ProgramFiles%\zSearch\
AUTST|zSearch
AUTST|Zstb.exe
UINST|zSearch_is1
FILEN|zsearch.dll
FILEN|zsearch.exe
FILEN|zstb.exe
NEWPR|1706|Townews
PRCAT|5
CLSID|{634efde4-087d-4ce9-952f-63c9eeb2e0bf}
NEWPR|565|TradeExit
PRCAT|5
CLSIA|{f0230524-9d39-4e84-8452-41c592961ea7}
FILEN|winupie.exe
NEWPR|2627|Transponder.kz515
PRCAT|5
CLSID|{c0322f4c-ab89-4c3b-94ae-56de8a4bd07d}
CLSID|{ed1282a6-4a6e-4893-85fc-6ccfd39d8377}
CLASS|kz515Dll.kz515DllObj
RKSOF|kz515
NEWPR|2372|Trojan.Zlob.E
PRCAT|5
CLSID|{1ca480cd-c0e5-4548-874e-b85b17905b3a}
CLSID|{724510c3-f3c8-4fb7-879a-d99f29008a2f}
CLSID|{7caf96a2-c556-460a-988e-76fc7895d284}
FILEN|%windir%\ncompat.tlb
FILEN|%windir%\system32\msvol.tlb
NEWPR|2814|TrustIn Bar
PRCAT|5
CLSID|{07a78aea-4a54-4967-9a60-4b68592d30c7}
CLSID|{23cb9697-2835-45c5-8949-8a4e73aa70d4}
CLSIA|{590ffb84-6a29-4797-9c0e-b15df2c4cdcb}
CLSID|{9b053e00-78d3-47ae-b763-60ff36ff2886}
CLSID|{fe6c16c4-16ad-47b6-b250-26ad1829e49a}
DIREC|%ProgramFiles%\TrustIn Bar
DIREC|%ProgramFiles%\TrustIn Contextual
DIREC|%ProgramFiles%\TrustIn Search
CLASS|InetLoader.WeeklyExecuter
CLASS|Se_spoof.SpoofBHO
CLASS|ticont.MyBHO
CLASS|tisa.MyBHO
CLASS|TrustIn.activator
CLASS|TrustIn.StockBar
CLASS|TrustInContext.ContextualAds
RKSOF|TrustIn
RKSOF|TrustIn Bar
UINST|Contextual Ads
UINST|TICONT
UINST|TISA
UINST|TrustIn Bar
NEWPR|2942|Trustin popups
PRCAT|5
DIREC|%programfiles%\TrustIn Popups\
AUTST|TrustIn Popups
RKSOF|TrustIn Popups
UINST|TrustIn Popups
FILEN|trustinpopups.exe
NEWPR|1352|Trustyfiles
PRCAT|5
DIREC|%ALLUSERSPROFILE%\TrustyFiles
DIREC|%programfiles%\TrustyFiles
RKSOF|TrustyFiles
UINST|TrustyFiles
FILEN|%USERPROFILE%\Desktop\TrustyFiles Downloads and Sharing.lnk
FILEN|%USERPROFILE%\Desktop\TrustyFiles.lnk
NEWPR|2635|TrustyHound
PRCAT|5
CLSID|{aa2ad390-5ec0-4742-a5f6-a59b50fbdaa0}
DIREC|%AllUsersProfile%\Start Menu\Programs\TrustyHound-TS\
DIREC|%ProgramFiles%\TrustyHound-TB\
DIREC|%ProgramFiles%\TrustyHound-TS\
AUTST|TrustyHound-TS
CLASS|ToolBand.XBTP01786
CLASS|XBTB01786.IEToolbar
CLASS|XBTB01786.XBTB01786
RKSOF|XBTB01786
UINST|TrustyHound-TS ( Companion Tools )_is1
UINST|XBTB01786.XBTB01786Toolbar
FILEN|%USERPROFILE%\Desktop\CardFountain Greetings.lnk
FILEN|%USERPROFILE%\Desktop\Free Stuff Directory.lnk
FILEN|%USERPROFILE%\Desktop\FunFlirts Online Dating.lnk
FILEN|%USERPROFILE%\Desktop\TrustyHound Image Search.lnk
FILEN|%USERPROFILE%\Desktop\TrustyHound Web Search.lnk
NEWPR|1086|TryToFind
PRCAT|5
CLSIA|{90baeb8b-47c2-44b4-a5a6-b99d34f1d4c5}
CLSIA|{d8c6179a-58c3-4662-800a-22dae7dcb152}
DIREC|%ProgramFiles%\Try2Find\
CLASS|sptbax.Install
RKSOF|Try2Find
NEWPR|1232|TurboDownload
PRCAT|5
CLSID|{120e090d-9136-4b78-8258-f0b44b4bd2ac}
CLSID|{1a00c40b-da85-4aa3-a67f-582d9347eecd}
DIREC|%programfiles%\Maxspeed
AUTST|IEDriver
RKSOF|MaxSpeed
RKSOF|turbodownload
NEWPR|521|TV Media Display
PRCAT|5
CLSID|{20ec3d2d-33c1-4c9d-bc37-c2d500688da2}
CLSID|{707e6f76-9ffb-4920-a976-ea101271bc25}
CLSID|{965a592f-8efa-4250-8630-7960230792f1}
DIREC|%ProgramFiles%\TV Media\
AUTST|TV Media
AUTST|TVMD
AUTST|winpoet
UINST|tv media
FILEN|%windir%\tvm_b5.exe
FILEN|tvmbho.dll
FILEN|tvmcore.dll
FILEN|tvmcwrd.dll
FILEN|tvmknwrd.dll
NEWPR|650|Twain-Tech
PRCAT|5
CLSID|{000020dd-c72e-4113-af77-dd56626c6c42}
CLSID|{0000607d-d204-42c7-8e46-216055bf9918}
AUTST|alchem
AUTST|djtopr1150.exe
AUTST|odurhdvxjj
AUTST|xgn
CLASS|Twaintec.TwaintecObj
CLASS|TwaintecDll.TwaintecDllObj
FILEN|mxtarget.dll
FILEN|twaintec.dll
NEWPR|2317|TX4
PRCAT|5
NEWPR|722|UCSearch
PRCAT|5
CLSID|{0ff7dbe0-ce7d-43b2-b016-50f1c88551e5}
CLSID|{1cbf31fc-3c23-4ba6-af16-2cec501bd837}
CLSIA|{1fdec088-a699-46fe-bf76-d5fd6dae6150}
CLSID|{4c33d68d-9703-4636-b433-383d42d0847c}
CLSID|{737263fd-a882-4957-8136-c0fd923ff150}
CLSID|{bbbe1c1a-89f7-4af6-abd1-f8fbcfa47408}
CLSIA|{e62a47d8-74b1-4a93-963a-e5e43b7cc5c2}
DIREC|%ProgramFiles%\open site\
CLASS|UCSearch.ucUCSearch
NEWPR|2666|Ultrabar
PRCAT|5
CLSID|{57a157fe-f766-46f1-8eb5-4a48be2f5daf}
CLSID|{a735e796-6ed4-4987-80e5-15b74020d978}
DIREC|%ProgramFiles%\UltraBar\
UINST|UltraBar
FILEN|%WINDIR%\Downloaded Program Files\ultrabar.inf
NEWPR|2011|Unclassified
PRCAT|5
NEWPR|3332|Unibar
PRCAT|5
CLSID|{0bbf1c37-f268-4489-8b0d-4e03f37a8dbf}
CLSID|{3221a442-e009-47f6-97c8-835462acc6b2}
CLSID|{77519220-81b7-4eff-9d40-5bc7425d4e5b}
CLSID|{841b2b65-118d-4ff2-ad63-4cff44b8b68f}
CLSID|{dbaed463-f7c8-4046-90ad-bef771cad496}
CLSID|{dfcb34b6-902d-426e-ae2b-1b294ae19f4f}
CLSID|{fd5ec997-35ab-49b6-a504-d0879643845f}
DIREC|%programfiles%\unibar\
CLASS|KWBand.CExplorerBar
CLASS|KWBand.KeyWordBand
UINST|21805fef
UINST|38616223
UINST|6fe46231
FILEN|unibar.exe
NEWPR|2099|UpSpiral Toolbar
PRCAT|5
CLSID|{4e7bd74f-2b8d-469e-deff-ed65a486aa28}
DIREC|%ProgramFiles%\Upspiral Toolbar\
CLASS|upspiral.UPSPIRAL
CLASS|upspiral.UPSPIRALMenu Button
CLASS|upspiral.UPSPIRALToggle Button
RKSOF|Upspiral Toolbar
UINST|Upspiral
NEWPR|743|URLBlaze
PRCAT|5
CLSIA|{9feffbde-fe2f-4756-b4a7-90d976255f9b}
CLSIA|{ce7c3cf0-4b15-11d1-abed-709549c10000}
DIREC|%programfiles%\urlblaze
DIREC|%USERPROFILE%\Start Menu\Programs\URLBlaze\
DIREC|%windir%\System32\IEDriver\
UINST|DMVLite
UINST|URLBlaze
FILEN|%SystemRoot%\uburl.dat
FILEN|%USERPROFILE%\Desktop\URLBlaze.lnk
NEWPR|742|Verticity
PRCAT|5
NEWPR|2614|VideoC
PRCAT|5
CLSID|{58dbce03-ffc3-4452-ab1d-c19ee9825a50}
NEWPR|1698|Viewpoint Media Toolbar
PRCAT|5
CLSID|{a7327c09-b521-4edb-8509-7d2660c9ec98}
CLSID|{f8ad5aa5-d966-4667-9daf-2561d68b2012}
DIREC|%allusersprofile%\Application Data\Viewpoint\ViewBar\
DIREC|%appdata%\Viewpoint\ViewBar\
DIREC|%programfiles%\Viewpoint\Viewpoint Toolbar\
CLASS|ViewBar.ViewBar
CLASS|ViewBarBHO.BHO
RKSOF|Viewpoint\ViewpointSearchBar
UINST|Viewpoint Manager
UINST|ViewpointSearchBar
NEWPR|2138|VipSearcher
PRCAT|5
CLSID|{0393fe81-0bbd-4bce-b4f2-c643aa7d77dd}
CLSID|{10bc40b5-5019-4a47-b033-308ca16d4959}
CLSID|{1559c6fd-8bde-476e-98c7-871e59193fce}
CLSID|{405132a4-5dd1-4ba8-a181-95c8d435093a}
CLSID|{c2e07b68-2f46-4dbb-8261-285794b7f8de}
NEWPR|1707|VirtuMonde
PRCAT|5
CLSID|{13589181-4f0d-4553-b9f8-b4b72172c139}
CLSID|{18722863-6d1d-4300-bf29-406948eda7cb}
CLSID|{30279f2d-1a38-4785-97d4-5c3508bdb289}
CLSID|{3ec8e271-fab9-418a-8a8e-65aeb4029e64}
CLSID|{446cf8a5-617e-4d91-95ae-ae78ce0d06af}
CLSID|{44e5b409-35a2-4e8d-bf94-344222323a53}
CLSID|{55e301e5-ba44-4095-bb0b-14e0123ccf71}
CLSID|{60112085-e1ce-4e0e-823a-ebb1ad98804c}
CLSID|{68132581-10f2-416e-b188-4e648075325a}
CLSID|{69eab151-c904-4734-aa74-a952290c5387}
CLSID|{6a06cdad-9d2d-42a0-9c91-c0cf7cb9971b}
CLSID|{6d33b121-5c4c-4450-9d1f-7b67085cc199}
CLSID|{72ac6865-b1d3-4c32-a27b-4b3bf04de655}
CLSID|{73529697-d46a-4f7d-8a93-01378fcaeda4}
CLSID|{77849d67-5672-4b68-93e2-cceff1e3949e}
CLSID|{8109af33-6949-4833-8881-43dcc232b7b2}
CLSID|{870b70d4-f6da-47ae-9158-d146440a0a4d}
CLSID|{bf755b85-ea69-4f58-9a59-d85f384a15ff}
CLSID|{c69fa570-7fde-4c49-a7bc-cb1cf24be66b}
CLSID|{d38439ec-4a7f-42b4-90c2-d810d7778fdd}
CLSID|{d6964fd8-3af1-4a2a-abb7-3d0c62924fd6}
CLSID|{d9511bf5-3c27-40ac-96da-2f439720efec}
CLSID|{df57feb6-9bce-45e3-aa65-be327b8cce7f}
CLSID|{ed5abc42-8e4f-4c39-9972-f0cf619d672f}
CLSID|{f32f8ecd-6cf3-459d-82f2-9738392c85a8}
CLSID|{fc148228-87e1-4d00-ac06-58dcaa52a4d1}
CLSID|{fd8609ec-7d7c-4778-ab8f-0053245550ef}
CLSID|{ff31c059-428b-4f07-bd1b-8f5dad170182}
AUTST|*catw
AUTST|ddayv
AUTST|pmnkk
AUTST|pmnlj
AUTST|windowsupd
FILEN|%systemroot%\system32\cbxwx.dll
NEWPR|2580|Virutek
PRCAT|5
AUTST|smsys
NEWPR|1811|Vividence Connector
PRCAT|5
CLSID|{c3bcc488-1ae7-11d4-ab82-0010a4ec2338}
NEWPR|2865|VMCleaner
PRCAT|5
NEWPR|2236|VoiceIP
PRCAT|5
REGKE|HKEY_CURRENT_USER\Software\VoiceIP
CLASS|VoiceIPDll.VoiceIPDllObj
NEWPR|912|Voonda Toolbar
PRCAT|5
CLSIA|{4e7bd74f-2b8d-469e-d4ff-eb2cf4d5fa7d}
NEWPR|1274|VroomSearch
PRCAT|5
CLSIA|{dab941d8-bc94-4819-ab4d-5598c65fa3fe}
CLSID|{f0c08b30-ba30-4feb-924b-2e250cf0697d}
AUTST|Tsa2
AUTST|Tsl2
NEWPR|3440|VSToolbar
PRCAT|5
CLSID|{74dd705d-6834-439c-a735-a6dbe2677452}
CLSID|{7addcf69-1cd5-4a57-8055-bb955805d918}
DIREC|%programfiles%\VSToolbar\
DIREC|%userprofile%\Local Settings\Application Data\VSolutions\
RKSOF|VSolutions
UINST|VSolutions Toolbar
FILEN|vsadd-in.dll
FILEN|vsolutions.exe
NEWPR|25|VX2
PRCAT|5
CLSID|{00000000-59d4-4008-9058-080011001200}
CLSIA|{00000000-5eb9-11d5-9d45-009027c14662}
CLSID|{00000026-8735-428d-b81f-dd098223b25f}
CLSID|{0000005d-c175-4405-bac5-1f3b2baf67c6}
CLSID|{00000062-2e5f-4af7-986e-5b64e0951a96}
CLSID|{00000097-7c67-4ba6-8b42-05128941688a}
CLSID|{0000026a-8230-4dd4-be4f-6889d1e74167}
CLSIA|{00000580-c637-11d5-831c-00105ad6acf0}
CLSID|{2cfb0ffd-a768-41d3-9b2d-059b80d03610}
CLSIA|{4cbbc676-507f-11d0-b98b-000000000000}
CLSID|{7632373d-4438-4d36-be59-22dc4dd85f41}
CLSIA|{a1a961da-2ba6-4032-859e-01ac35357163}
CLSIA|{ffd2825e-0785-40c5-9a41-518f53a8261
AUTST|Belt
AUTST|kkqejwjaqtb
AUTST|ntechin
AUTST|popuppers64
AUTST|satmat
AUTST|SysStart
AUTST|xqkako
AUTST|ZStart
CLASS|SiteHlpr.SiteHlprObj
CLASS|VX2.VX2Obj
RKSOF|TPS108
FILEN|%systemroot%\system32\vx0.nls
FILEN|%systemroot%\system32\vx1.nls
FILEN|%systemroot%\system32\vx1x.nls
FILEN|%systemroot%\system32\vx2.nls
FILEN|%systemroot%\system32\vx2x.nls
FILEN|%systemroot%\system32\vx3.nls
FILEN|%systemroot%\vx0.nls
FILEN|bi_prob.exe
FILEN|msview.dll
FILEN|sysvx.exe
FILEN|tps108.cab
FILEN|tps108.dll
FILEN|vx2.dll
NEWPR|630|W32.Hawawi.Worm
PRCAT|5
CLSID|{3df2ae33-26a8-11d4-bdd2-00104bfec09f}
CLASS|smtpcontrol.smtp
NEWPR|484|Wazam
PRCAT|5
CLSIA|{b5e60a66-0c51-4894-8df8-cbdf4e478d58}
NEWPR|898|WeatherScope
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Weatherscope
DIREC|%ProgramFiles%\Weatherscope
RKSOF|Gator.com\Gator\dyn\GCH\_weather
RKSOF|Gator.com\Weatherscope
RKSOF|Weatherscope
UINST|Weatherscope
FILEN|%userprofile%\desktop\WeatherscopeSetup.exe
FILEN|weatherscope website.lnk
FILEN|weatherscope.exe
FILEN|weatherscopesetup.exe
NEWPR|634|Web behavior
PRCAT|5
CLSIA|{0054ad19-7e4e-4ae4-b275-20f237280f5c}
CLSIA|{645d793b-33e2-4175-a7e1-ba490839358a}
NEWPR|1237|Web3000
PRCAT|5
AUTST|w3knetwork
RKSOF|web3000.com
UINST|textwiz_is1
UINST|web3000 network
UINST|xtractor plus_is1
NEWPR|2525|WebBullion
PRCAT|5
RKSOF|VB and VBA Program Settings\webbullion
NEWPR|2134|Webcrawler
PRCAT|5
CLSID|{9677f3f1-e994-451f-805f-7148cc8ae040}
NEWPR|2517|WebDir
PRCAT|5
CLSID|{453dca38-2a09-4dbe-a617-a2711c8480d0}
CLSID|{c003c49f-53e4-4a72-b7d6-0b2b9997392f}
CLSID|{e7bf2c44-c0cc-4592-8349-0f899ada5447}
REGKE|HKEY_CLASSES_ROOT\AppID\webdir.DLL
CLASS|webdir.WebDirObj
NEWPR|26|WebHancer
PRCAT|5
CLSID|{c89435b0-cdfe-11d3-976a-00e02913a9e0}
CLSID|{c8cb3870-cdfe-11d3-976a-00e02913a9e0}
CLSID|{c900b400-cdfe-11d3-976a-00e02913a9e0}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\webHancer Agent
DIREC|%allusersprofile%\Start menu\Programs\WinAntiVirus Pro 2006
DIREC|%programfiles%\em\
DIREC|%programfiles%\mm\
DIREC|%programfiles%\webhancer\
DIREC|%programfiles%\whInstall\
WINDO|whAgent
AUTST|webhancer agent
AUTST|webhancer survey companion
CLASS|whiehelperobi.whiehelperobj
CLASS|whiehelperobj.whiehelperobj
RKSOF|WebHancer
RKSOF|whsurvey
UINST|webhancer agent
UINST|whsurvey
FILEN|wbhshare.dll
FILEN|webhdll.dll
FILEN|whagent.exe
FILEN|whagent_update.exe
FILEN|whcc-giant.exe
FILEN|whcc_realeuser.exe
FILEN|whiehlpr.dll
FILEN|whieshm.dll
FILEN|whinstaller.exe
FILEN|whsurvey.exe
NEWPR|769|Websearch
PRCAT|5
CLSID|{1ff04b25-0a23-4a12-960c-73f8b9950436}
CLSID|{234f09fb-fe89-4c6d-9203-31832fc051c3}
CLSID|{365b9a54-e613-46e5-9db1-4f91a9de80bd}
CLSID|{37ac49e3-e906-4bd8-ae83-d0f7fb48fd17}
CLSID|{618be527-b7f5-417c-bc51-98fdc2d6de61}
CLSID|{66c22569-f05c-4a70-a142-763b337e1002}
CLSID|{69357d4e-bf4d-4651-91e9-52ecd45a0128}
CLSID|{6e21f428-5617-47f7-aed8-b2e1d8fba711}
CLSID|{6f59d850-a155-4930-98ae-689a2bc7b8e8}
CLSID|{708be496-e202-497b-bc31-9cf47e3bf8d6}
CLSID|{7b8bd940-b1ef-460c-85a2-9acaaf7f9303}
CLSIA|{87067f04-de4c-4688-bc3c-4fcf39d609e7}
CLSIA|{886dde35-e955-11d0-a707-000000521958}
CLSID|{99aa88d1-d9d3-410a-be9e-044f94c183da}
CLSID|{af8b3c81-cd19-45fb-b6be-160d27711de8}
CLSID|{bbf122a7-8a4d-45b5-9e00-0f68bc87c904}
CLSID|{c380566d-f343-42ab-987b-6b38a1a35747}
CLSID|{cabcf5e7-0c79-4f1c-909d-b9cf68fed746}
CLSID|{cae0999f-78c5-49dc-9f30-13142aaaaba4}
CLSID|{d1951679-1d52-43fc-9585-0737143585f5}
CLSID|{d8bd4ded-5bb2-4d4e-9a6a-f10244fed7d6}
CLSID|{db9a4e78-35df-4a54-b6c5-c5190ceaf949}
CLSIA|{e4463a35-7e7a-4621-8248-91307afa8ead}
CLSID|{f1616b86-9288-489d-b71a-0ccf2f1a89da}
CLSID|{f273d4ea-2025-4410-8408-251a0cd46be7}
CLSID|{fb45c451-b0e9-4407-bb6a-9361013f3e9a}
DIREC|%ALLUSERSPROFILE%\Start Menu\ProgramsWeb Search Tools\
DIREC|%programfiles%\websearch\
AUTST|ir50_32
AUTST|Mmgsvc
AUTST|Narrator
AUTST|Pfkezr
AUTST|SAK
AUTST|TBPS
AUTST|TBPSSvc
AUTST|websearch
RKSOF|toolbar
FILEN|%programfiles%\Toolbar\tbps.dat
FILEN|edowst3.exe
FILEN|zcwedowst3.exe
NEWPR|1201|WebSecurealert
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\WebSecurealert\
DIREC|%ALLUSERSPROFILE%\WebSecurealert
DIREC|%ProgramFiles%\WebSecurealert
RKSOF|Gator.com\WebSecurealert
RKSOF|WebSecurealert
UINST|WebSecurealert
FILEN|websecurealert.exe
FILEN|websecurealertsetup.exe
FILEN|websecureuninstaller.exe
FILEN|wsahelper.dll
NEWPR|2553|WebThisWebThat
PRCAT|5
DIREC|%allusersprofile%\Start Menu\Programs\wtwt\
DIREC|%ProgramFiles%\wtwt\
UINST|wtwt
NEWPR|543|Whazit
PRCAT|5
CLSID|{10955232-b671-11d7-8066-0040f6f477e4}
CLSIA|{267d5bd3-0dc2-4724-a196-7f4794fbb9eb}
CLSIA|{3b99f202-145a-4e5a-ac7b-88a36910bf5e}
CLSIA|{66f67511-2665-4c34-9e20-fac2c0954ef2}
CLSID|{c9176930-9c9f-4cba-9723-0f58c3e7ced6}
CLSIA|{ce156487-4d41-4e86-98cf-56115b9185ce}
CLSID|{d130f0d2-bcfd-4b15-a5e7-415159ef4969}
CLSID|{d5b72aed-e54a-11d6-b1b2-444553540000}
CLSIA|{d7d7004c-a763-4f8c-b0d4-55a7e017e69d}
CLSIA|{dcf0768d-ba7a-101a-b57a-0000c0c3ed5f}
CLASS|BrowserHelper.CBrowserHelper
CLASS|wharederer.Class1
RKSOF|180solutions\msbb
RKSOF|wms
UINST|redwhazit
FILEN|whattn.dll
NEWPR|2230|WhenU-BrowserToolbar
PRCAT|5
CLSID|{45e5dadb-dfdf-4fc3-a46c-dd34b6cddb38}
CLSID|{763bd795-24ae-44d7-82d8-f9a1ee799729}
CLASS|WUSE
UINST|WhenUSearchB
FILEN|%userprofile%\Local Settings\Temp\is-1PA2S.tmp
FILEN|%userprofile%\Local Settings\Temp\is-C0QLG.tmp
NEWPR|871|WhenU-ClockSync
PRCAT|5
DIREC|%programfiles%\ClockSync\
AUTST|ClockSync
UINST|ClockSync
FILEN|vvsni_sync_webinst.exe
NEWPR|18|WhenU-DesktopBar
PRCAT|5
CLSID|{20c9d850-244d-10e1-b3c1-20805e499d95}
CLSID|{711648f0-5ff5-4c81-805e-a1aedbab4951}
CLSID|{715839cd-abec-45d8-a83c-1275f2d837cd}
CLSID|{737830b7-f1f9-4bae-a8fc-1433c71bedff}
CLSID|{ba2325ed-f9eb-4830-8fce-0bc35b16969b}
CLSID|{beae14db-a12a-442d-bf77-4644e3661211}
CLSID|{c285d18d-43a2-4aef-83fb-bf280e660a97}
CLSIA|{e2f2b9d0-96b9-4b25-b90c-636ecb207d18}
CLSIA|{fc327b3f-377b-4cb7-8b61-27cd69816bc3}
CLSIA|{fee7fd53-3356-4d4d-8978-2c4ae3a7e109}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WUSE.1
DIREC|%programfiles%\VVSDL
DIREC|%programfiles%\VVSN
DIREC|%PROGRAMFILES%\WHENUSEARCH\
DIREC|%USERPROFILE%\Start Menu\Programs\WhenU
DIREC|%USERPROFILE%\Start Menu\Programs\WhenUSearch
WINDO|WhenUOffers
AUTST|SARU
AUTST|VVSN
AUTST|WhenUSearch
AUTST|WhenUSearchWHSE
CLASS|WhenU
RKSOF|WhenU
RKSOF|whenusearch
UINST|whenusearch
FILEN|%alluserprofile%\Desktop\Toolbar.lnk
FILEN|vvsn.exe
FILEN|whse_pb.min.g2inst.exe
NEWPR|2485|WhenU-FanzoneToolbar
PRCAT|5
FILEN|vvsn_fanz0110inst.exe
NEWPR|1149|WhenU-PriceBandit
PRCAT|5
AUTST|WhenUStart.exe
RKSOF|WhenUShop
UINST|whenushop
FILEN|vvsni_pbtb0100inst.exe
NEWPR|2376|WhenU-SaveNow
PRCAT|5
CLSID|{127df9b4-d75d-44a6-af78-8c3a8ceb03db}
CLSID|{43382522-a846-46f4-ac57-1f71ae6e1086}
CLSID|{572fb162-c0ba-4edf-8cff-e3846153b9b0}
CLSID|{72a836d1-bc00-43c0-a941-17960e4fb842}
CLSID|{a9aae1ab-9688-42c5-86f5-c12f6b9015ad}
CLSID|{df901432-1b9f-4f5b-9e56-301c553f9095}
REGKE|HKEY_CLASSES_ROOT\AppID\ACM.DLL
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WUSN.1
DIREC|%CommonProgramFiles%\WhenU\
DIREC|%programfiles%\savenow\
DIREC|%programfiles%\save\
DIREC|%programfiles%\VVSDL\
DIREC|%USERPROFILE%\Start Menu\Programs\WhenU\
AUTST|SaveNow
AUTST|Vicman_WhenUSave_Installer
AUTST|WhenUSave
CLASS|ACM.ACMFactory
CLASS|ACM.DLL
CLASS|WhenU.SiteSupport
CLASS|wusn
RKSOF|WhenUSave
UINST|SaveNow
UINST|WhenUSaveMsg
FILEN|saveinstcm.exe
FILEN|saveuninst.exe
FILEN|saveupdate.exe
FILEN|setupsavenow.exe
FILEN|vvsni_savenowsiteinst.exe
NEWPR|2396|WhenU-UControl
PRCAT|5
CLSID|{0a65ca2b-edb9-48b1-92da-1d92c72498e4}
CLSID|{0c4c45db-a4dc-4cf4-8f1d-8cadf97855c9}
CLSID|{28d4752f-cf84-11d1-834c-00a0249f0c28}
CLSID|{5b061650-38ae-49b4-9f5d-35396b2ceff5}
CLSID|{70271f18-b604-40fe-a8cd-15baeb11ed84}
CLSID|{8cbdba78-8cd5-4037-bd94-67cd49958d23}
CLSID|{916d4be3-6b0f-4e73-871a-17bd6ef3b2f9}
CLSID|{a001a440-e479-4fa9-8270-2cc9f0e69e2c}
CLSID|{c831c7c9-e46c-45f2-b44e-b7f72e2a9a1d}
CLSID|{cb8acef9-1085-4b47-b969-963e56aa9543}
CLSID|{f3208e7f-0e66-4f1d-bab9-ef7ec870ed24}
DIREC|%allusersprofile%\All Users\Application Data\Ucontrol\
DIREC|%CommonprogramFiles%\Ucontrol\
CLASS|UControlScanAndRemove.UControlScanner
CLASS|wss_sp_gen.Class1
CLASS|wss_sp_reg.Class1
RKSOF|Ucontrol
UINST|UControl Scan and Remove
NEWPR|2377|WhenU-WeatherCast
PRCAT|5
CLSID|{20752c25-2d97-4e6f-9ee2-94b74d202875}
CLSID|{389a5a59-1306-4389-a779-2eb9d0bc1ffb}
DIREC|%ProgramFiles%\WeatherCast\
DIREC|%USERPROFILE%\Start Menu\Programs\WeatherCast\
AUTST|WeatherCast
CLASS|WhenU.EmbedSE
RKSOF|WhenU\Weather
UINST|WeatherCast
FILEN|setupweathercast.exe
FILEN|sndbmark.dll
FILEN|weatherautocast0007.cab
FILEN|weatherautocast0018.cab
FILEN|weatherautocast0021.cab
FILEN|weatherinst.exe
FILEN|weatherinstcast0004.cab
FILEN|weatherinstcast0203.cab
FILEN|weatherinstcast1113.cab
FILEN|weatherinstibon0001.cab
FILEN|weatherinstslct0002.cab
NEWPR|2461|WhileYouSurf
PRCAT|5
UINST|While You Surf
NEWPR|2337|WhistleSoftware
PRCAT|5
CLSID|{0a88c7a6-f482-462a-8f43-f1ad8c009f50}
CLSID|{0bf6b2ca-be97-4275-8695-2
fb086be0b9b}
CLSID|{0cc38e71-6ad3-450c-8c71-50728a640b43}
CLSID|{0fbd6033-24c5-45d2-a1e5-38c46ed3b135}
CLSID|{220e39c3-b081-4719-ab1a-9a884dcbd05c}
CLSID|{27557cf1-a237-496d-8c8f-08f3844c6a8b}
CLSID|{322400d5-8fb0-45ba-8f09-0e837d57493b}
CLSID|{3fecb959-1fdd-4803-850a-ca3f2859f5ab}
CLSID|{54a770f4-d5f3-42ae-9fd5-390a6a4d85e7}
CLSID|{568f3ba7-b0e2-4a83-b8b6-319631c4622c}
CLSID|{7ea005fe-90da-4bc7-955b-9face4a2069c}
CLSID|{80e6ee09-3db1-4627-a7c9-dad7cfbdf05f}
CLSID|{8179b6d6-513d-45dc-b910-aa329a524142}
CLSID|{889395bf-f7f7-4023-b42e-6074de380ea5}
CLSID|{8d9bffc9-e027-4ea3-8ae9-8dbefed2fb93}
CLSID|{8da46338-ba81-4065-b7b9-36450e42b017}
CLSID|{92a17f40-e69b-44fa-9b8a-aaf7dbe413af}
CLSID|{930cb039-564e-4c04-b6a8-8b31bfb28347}
CLSID|{93cf2521-df05-41f4-b803-5eb17c4bb424}
CLSID|{99258154-5666-4561-ad45-c76ae7077b70}
CLSID|{9f05772f-c5ab-4491-b8e1-a5a1a0b883a7}
CLSID|{a16e4ecf-12aa-49e2-9891-ece57af678b9}
CLSID|{a58aacf2-6e0f-4465-8c81-52151e60e07b}
CLSID|{a625720f-c6eb-4806-b3d6-8fc4df89db94}
CLSID|{aa5955f9-b090-4d3b-ad7f-c9b46509bb87}
CLSID|{ac8b00eb-0b68-49a6-a278-cbba09e8151e}
CLSID|{b135ed26-a131-4861-b081-35c69398a704}
CLSID|{b8848f69-e8e2-4952-90f2-bc4ef0c22243}
CLSID|{bb46ac71-9f97-4518-b0d0-f3008b65cf88}
CLSID|{c7a2084b-969c-439a-96e8-176bf9a93879}
CLSID|{d02fac77-c2e0-44d9-aa62-e9f40831ca8e}
CLSID|{d1bcd273-d241-4bff-a2a0-e45b3b4eb27b}
CLSID|{d5e6a641-453e-4650-a49a-fa912a870827}
CLSID|{ebcf7b0e-2277-4ee4-95ee-3d542cdb8191}
CLSID|{f75448f7-4f62-45fa-9bc1-4250bb4d87c9}
CLSID|{fdc2fa83-0e09-427a-a4e6-04fb98667c32}
CLSID|{fe2c03f1-eb17-4017-9c22-99c65870b9ec}
DIREC|%ProgramFiles%\WhistleSoftware\
CLASS|IMCUpdate.Update
CLASS|ImcWselParser.WselParser
CLASS|WhistleHlprObj.WhistleHlprObj
CLASS|WselServices.WselLogServices
CLASS|WselServices.WselNetworkServices
CLASS|WselServices.WselXmlServices
CLASS|WselTypeLibrary.User
CLASS|WselTypeLibrary.WselService
CLASS|WselTypeLibrary.WselServiceCol
RKSOF|WhistleSoftware
UINST|Whistle Software
NEWPR|2058|WierdontheWeb
PRCAT|5
DIREC|%programfiles%\WeirdOnTheWeb\
AUTST|WeirdOnTheWeb
RKSOF|WeirdOnTheWeb
UINST|WeirdOnTheWeb
FILEN|%userprofile%\favorites\weirdontheweb.url
FILEN|weirdontheweb_topc.exe
NEWPR|2216|Win32.Stervis.b
PRCAT|5
SERVK|SvcProc
NEWPR|2522|Wina
PRCAT|5
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WinA
DIREC|%ProgramFiles%\WinA\
UINST|WinA
NEWPR|796|WinAd
PRCAT|5
CLSID|{002eb272-2590-4693-b166-fbd5d9b6fea6}
CLSID|{53d3c442-8fee-4784-9a21-6297d39613f0}
DIREC|%ProgramFiles%\Winad Client
AUTST|Winad Client
AUTST|WNAD
NEWPR|2764|Winadiscount Toolbar
PRCAT|5
CLSID|{4961a993-7f48-4c50-a30e-d597ac571707}
CLSID|{4e7bd74f-2b8d-469e-87be-a334b786b339}
DIREC|%ProgramFiles%\winadiscount\
CLASS|winadiscount.WINADISCOUNT
CLASS|winadiscount.WINADISCOUNTMenu Button
CLASS|winadiscount.WINADISCOUNTToggle Button
RKSOF|winadiscount
UINST|winadiscount
NEWPR|2688|Windows AdService
PRCAT|5
DIREC|%ProgramFiles%\Windows AdService\
AUTST|Windows AdService
RKSOF|Windows AdService
UINST|Windows AdService
NEWPR|3298|Windows FastS Toolkit
PRCAT|5
CLSID|{e3231ba4-4271-402e-b20c-d5cfff70f9d4}
AUTST|fasts_on
RKSOF|fasts
UINST|fasts
NEWPR|775|Windows Search Bar
PRCAT|5
CLSID|{9fb534e3-67cb-4307-ae0a-9e8b5581be2c}
CLSID|{a1dd937d-71e1-4bb5-bd5d-1b01b9cb1c2f}
NEWPR|1148|Windupdates
PRCAT|5
CLSIA|{15ad4789-cdb4-47e1-a9da-992ee8e6bad6}
CLSIA|{15ad6789-cdb4-47e1-a9da-992ee8e6bad6}
CLSID|{962f12ae-2773-4beb-99ea-b5c3ab9a6606}
DIREC|%programfiles%\Admilli Service
DIREC|%programfiles%\AdTools Service
DIREC|%ProgramFiles%\DeskAd Service
DIREC|%programfiles%\winad client\
DIREC|%programfiles%\windows adcontrol
DIREC|%ProgramFiles%\Windows AdTools
DIREC|%ProgramFiles%\Windows ControlAd
DIREC|%ProgramFiles%\Windows ServeAd
DIREC|%programfiles%\windows taskad
DIREC|%programfiles%\windupdates\
AUTST|Admilli Service
AUTST|AdTools Service
AUTST|DeskAd Service
AUTST|Media Access
AUTST|msccrt
AUTST|qfyqakn.dll
AUTST|system spool
AUTST|Windows AdTools
AUTST|Windows ControlAd
AUTST|Windows ServeAd
AUTST|Windows TaskAd
AUTST|WindUpdates
AUTST|winform
AUTST|winupdate
AUTST|winupdtl
CLASS|AdManCtlx.Installer
CLASS|BridgeX.Installer
CLASS|MediaAccX.Installer
CLASS|WinadX.Installer
CLASS|WinStatX.Installer
RKSOF|Admilli Service
RKSOF|AdStatus Service
RKSOF|AdTools Service
RKSOF|DeskAd Service
RKSOF|Preview AdService
RKSOF|t5c
RKSOF|t5d
RKSOF|t5e
RKSOF|t5f
RKSOF|t5r
RKSOF|Windows TaskAd
RKSOF|WindUpdates
RKSOF|WinUpdt
UINST|Admilli Service
UINST|AdTools Service
UINST|DeskAd Service
UINST|Wind Updates
UINST|Windows TaskAd
FILEN|%windir%\system32\netut80ex.vxd
FILEN|%windir%\system32\winup2date.dll
FILEN|%windir%\system32\winupdt.008
FILEN|%windir%\system32\winupdt.bin
FILEN|bridge-c18.cab
FILEN|mediaaccess.exe
FILEN|mediaacck.exe
FILEN|winad.exe
FILEN|winctladshift.dll
FILEN|winka.exe
NEWPR|942|WinFavorites
PRCAT|5
CLSID|{4fdbdbad-fefe-4c4c-9cc1-1181052afb12}
CLSID|{80bb7465-a638-43b5-9827-8e8fe38dfcc1}
CLSID|{b88a3af1-4f1b-4400-8ffb-3fcb108ce115}
CLSID|{c094876d-1b0e-46fa-b6a6-7ffc0f970c27}
CLSID|{ddaf2479-6f00-4599-998a-3ed75686c6d0}
DIREC|%programfiles%\winfavorites
AUTST|oljxtggp
AUTST|WinFavorites
CLASS|bridge.brdg
RKSOF|winfavorites
UINST|win favorites
NEWPR|1712|WinFetcher
PRCAT|5
AUTST|imr1x
NEWPR|1443|Winpage
PRCAT|5
CLSID|{12df6e3e-6272-4ae8-880b-2158d60791c0}
CLSID|{c4c16842-a83e-4fc1-b9ef-995f764da9b2}
CLSID|{f31ef3c5-dabf-4258-9cb8-b11b52c94d8c}
DIREC|%ProgramFiles%\Homepage
CLASS|WinPageBHO.DLL
CLASS|WinPageBHO.WinPageIEExtension
NEWPR|624|Winpup
PRCAT|5
CLSIA|{9387b9e0-3da2-436e-88e5-fa09ae3a48c0}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\pup
AUTST|asauthr
AUTST|dhcpv
AUTST|dwwizh
AUTST|qlsrv32s
AUTST|svidc32m
AUTST|win32app
CLASS|pup.setup
RKSOF|pup
NEWPR|609|Winshow
PRCAT|5
CLSIA|{6cc1c918-ae8b-4373-a5b4-28ba1851e39a}
DIREC|%APPDATA%\winshow\
CLASS|WinShow.ViewSource
RKSOF|WinShow
FILEN|msupdater.exe
FILEN|winshow.dll
NEWPR|1136|Winspoe
PRCAT|5
CLSID|{043b5d00-92a9-4cae-a3d8-a4b4b8d52bb1}
NEWPR|2352|Winsync
PRCAT|5
CLSID|{6ec11407-5b2e-4e25-8bdf-77445b52ab37}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\woualo
UINST|WebNexus
FILEN|mynexus.exe
FILEN|webnexus.exe
NEWPR|1784|WishBone
PRCAT|5
CLSID|{08e62c6d-babd-4be9-a015-ecfe9cc76997}
CLSID|{10cd7efc-7d1a-4599-ab49-9249c714b87c}
CLSIA|{3aa90bc2-58c0-4f4d-a87c-2c6f3d3cd5fe}
CLSID|{40930a0f-68cc-4b81-848a-77a78f85fa7b}
CLSID|{4fd85670-606a-42e9-bba5-2bc63493b677}
CLSID|{86f4ad51-ee90-409d-944b-fdb0c939b41c}
CLSID|{87b1e57c-ff70-4c69-9ce8-57cb8f67aba8}
CLSID|{aeef5ccc-71c7-4053-88a4-6cb87fd4e461}
CLSID|{b004262d-5762-4daa-a222-3b9a738c83ea}
CLSID|{b0931261-03c3-4bb3-9ce1-22bfda3af445}
CLSID|{b6ce642a-2171-4661-bb46-aed01c2ed9ec}
CLSID|{c331bd6e-06ab-41a0-b95f-d7ca379aceaa}
CLSID|{cc4a4cd1-e441-4a03-941c-e183bce357e7}
CLSID|{da3db988-d1fb-4919-a684-78e6a5358340}
CLSID|{db2e7bc7-104f-42b5-aae3-921e3057db06}
CLSID|{eaa87376-c391-494e-9da2-2bd9c798e54f}
DIREC|%WINdir%\system32\WBM\
CLASS|Gigel.ScriptCallback
CLASS|Keys.KeyWords
CLASS|MenuContainer.MenuHolder
CLASS|MenuContainer.RegAcess
CLASS|MenuContainer.WebSink
CLASS|MicroInstaller.WBMInstaller
CLASS|WBM.AtlBrCon
CLASS|WBM.ExplorerBar
CLASS|WBM.WebMonitor
CLASS|Wbmbar.ViewSource
CLASS|Wbmbar.WBMToolBar
RKSOF|WBInstaller
RKSOF|WBM
RKSOF|Wishbone Media
UINST|WBInstaller
NEWPR|29|WNAD
PRCAT|5
FILEN|wnad-update.exe
FILEN|wnad.exe
NEWPR|1713|Wotch
PRCAT|5
AUTST|media_manager
AUTST|media_stub
NEWPR|483|WurldMedia
PRCAT|5
CLSID|{01fb9c55-fc66-4476-a199-389241193188}
CLSIA|{1b80440d-b4c0-49d7-8d2f-77f16777629b}
CLSIA|{2737a6c0-7e24-11d7-b299-00e0297e0844}
CLSIA|{3a279869-c6b6-4410-a041-0435de6ad916}
CLSIA|{40ac4d2d-491d-11d4-aaf2-0008c75dcd2b}
CLSID|{48f35889-7f47-4a93-8876-7ab20324e5d7}
CLSID|{525bbd23-1863-46c6-86d6-5f9a3715d44e}
CLSIA|{5a3a5040-4210-11d7-bd2e-00080e34122f}
CLSIA|{6270dfc1-edfb-4bc4-be8c-842740ba290b}
CLSIA|{8a880893-e6b2-4c29-b168-181a4ef6b852}
CLSID|{8e9c4f32-bd3f-4c49-9af5-3f4c5d32ebd7}
CLSIA|{98d7b53e-b1d2-4755-b0a4-703e18ff91e8}
CLSID|{a83e42b1-1ae7-4ce6-b128-ab0f4a126b2c}
CLSIA|{bfbae8da-9920-4166-a5a4-ebd03f59abf5}
CLSIA|{cdbcfeae-10ba-482c-9f6e-fc67207082d8}
CLSIA|{d14641fa-445b-448e-9994-209f7af15641}
CLSIA|{f325e940-45ee-11d7-a420-444553540000}
CLASS|Mobho.IEHlprObj
CLASS|Tchk.TChkBHO
RKSOF|morp
RKSOF|rdxr
FILEN|bpboh.dll
FILEN|m030106shop.dll
NEWPR|2933|X Password Manager
PRCAT|5
DIREC|%ProgramFiles%\X Password Manager\
DIREC|%userprofile%\Start Menu\Programs\X Password Manager\
UINST|X Password Manager
FILEN|%userprofile%\Desktop\X Password Manager.lnk
NEWPR|2702|Xagon - Atomic Mp3 Finder
PRCAT|5
DIREC|%ProgramFiles%\Xagon\
RKSOF|Xagon
UINST|Atomic Mp3 Finder
NEWPR|2587|Xbarre
PRCAT|5
CLSID|{4e7bd74f-2b8d-469e-d7ec-ed6db68dfa7d}
CLSID|{4e7bd74f-2b8d-469e-d7ec-ed6db68dfa7e}
CLSID|{4e7bd74f-2b8d-469e-d7ec-ed6db68dfa7f}
DIREC|%ProgramFiles%\xbarre\
CLASS|xbarre.XBARRE
CLASS|xbarre.XBARREMenu Button
CLASS|xbarre.XBARREToggle Button
RKSOF|XBARRE
UINST|XBARRE
NEWPR|1828|Xhrmy
PRCAT|5
AUTST|xhrmy
RKSOF|Xhrmy
NEWPR|1220|Xlocator/Winlocator
PRCAT|5
CLSIA|{121ac498-3f3a-4c39-9bea-cfc4ea809fdf}
CLSID|{89aeab46-8e8a-4045-9003-5614bfbfe90b}
CLSID|{8f0d6eed-bc11-4e7f-8276-9748947e4a50}
AUTST|winlocatorupdate
CLASS|WinLocator.Portal
CLASS|WinLocatorHelper.bho
CLASS|XlocatorInstall.Install
RKSOF|winlocator
FILEN|%WINdir%/winlocator.reg
NEWPR|1234|Xrenoder
PRCAT|5
UINST|AutoUpdate
NEWPR|430|Xupiter
PRCAT|5
CLSID|{07fa131e-2eb2-446f-93d2-9f877320010b}
CLSID|{1348e05a-21c7-4134-b4a4-3c12234fca3f}
CLSID|{1a8b567b-bd3f-44a1-8b94-f50d37a1914e}
CLSID|{2662bdd7-05d6-408f-b241-ff98face6054}
CLSIA|{280168bc-76bf-4cd0-b835-3d686efa8ddc}
CLSID|{29089b98-af05-4769-b627-86a745d4b672}
CLSID|{3a021d2f-5f75-47f5-9bab-a137e1fb015f}
CLSIA|{3c5ba506-6c30-4738-9ced-797acadea8dc}
CLSID|{3f4386e5-2fbe-44a8-81cf-4b792490605f}
CLSID|{43732063-1bda-45a0-bbee-13e014cb4041}
CLSID|{43f1b4ad-92ef-4db3-bda9-12335b012dd0}
CLSID|{4a0f42b7-a61b-4131-bf41-bf05a2635bfd}
CLSID|{55b201ff-c057-e521-6d17-0489b6cf9930}
CLSIA|{57e69d5a-6539-4d7d-9637-775de8a385b4}
CLSID|{6e6dd93e-1fc3-4f43-8afb-1b7b90c9d3eb}
CLSIA|{702ad576-fddb-4d0f-9811-a43252064684}
CLSID|{74232635-a013-49f2-b869-1b1ab932d944}
CLSID|{7f0f5d9a-84cb-11d4-8137-00500487b1c5}
CLSID|{7f0f5da6-84cb-11d4-8137-00500487b1c5}
CLSID|{83b027c5-1489-4ec5-a290-47da8058ac04}
CLSID|{899be974-d575-48bb-a9c7-1d24e8042be4}
CLSID|{8bee173b-c006-4f0e-acd2-84a882bebcff}
CLSID|{909e0059-f545-42de-9d2c-cc4a3e336ec3}
CLSID|{910e67a6-bd53-46df-8434-41498b7d22f7}
CLSID|{9464c98e-b5f1-4c6a-bd3f-9696e3bd081e}
CLSID|{9dbdd71c-0a7f-48ac-9ffa-e102b3750b9d}
CLSIA|{a27cfcae-9351-4d74-bffc-21eb19693d8c}
CLSID|{b0db6360-8d7f-11d4-8137-00500487b1c5}
CLSID|{bf986691-7f7b-4f94-85e0-20e75350701f}
CLSID|{bfa2c963-fc24-4770-8c19-0d5a1cd58df9}
CLSID|{c09fb84d-b9ed-43eb-afed-f145c26cb839}
CLSID|{c0cad17e-00a3-4f40-9015-d569c3114ba3}
CLSID|{c2e56e18-2f04-4ab9-9333-b2db3c350956}
CLSID|{c6c2871f-7467-4a35-90fa-9e9894bc1916}
CLSID|{c81b4b57-b06b-409d-aed0-028051683796}
CLSID|{ce2eab19-e31d-43ca-a860-f95a2ca50040}
CLSIA|{d48f2e28-68e2-4920-9848-d6e6c7ab3eb7}
CLSID|{d686db39-659a-491a-a35c-60b99495c16e}
CLSIA|{d7b3e460-9968-4191-bd6f-beed1bc18482}
CLSID|{e9cbbeed-20b6-456c-8589-cf364d9d2370}
CLSID|{eb07a6d3-8e36-11d4-8138-00500487b1c5}
CLSID|{f8c5ea77-7d72-405c-b90a-093655b0f544}
CLSID|{ffe56921-248b-4c75-9eee-01706310e371}
DIREC|%programfiles%\Sqwire\
DIREC|%programfiles%\Xupiter\
AUTST|buwhtje.dll
AUTST|xupitercfgloader
AUTST|XupiterStartup
CLASS|xtsearch.xtsearchhook
CLASS|xtupdate.xt
CLASS|xupitertoolbar.band
RKSOF|Xupiter
UINST|Xupiter
FILEN|bobsaver.exe
FILEN|bobsaver.scr
FILEN|oeloader.dll
FILEN|popunder.exe
FILEN|tsl_rc0.dll
FILEN|xtcfgloader.exe
FILEN|xtcfgrunner.exe
FILEN|xtsearch.dll
FILEN|xtupdate.dll
FILEN|xupiterstartup.exe
FILEN|xupiterstartup2003.exe
FILEN|xupitertoolbar.dll
FILEN|xupitertoolbarinstaller.exe
FILEN|xupitertoolbarloader.cab
FILEN|xupitertoolbarloader.exe
FILEN|xupiterwauninstaller.exe
NEWPR|2426|Xware
PRCAT|5
CLSIA|{42b1c70d-9823-41f7-810a-682da294d868}
AUTST|sload
AUTST|xware
IEZON|xxsware.com
NEWPR|610|xxxtoolbar
PRCAT|5
CLSIA|{386a771c-e96a-421f-8ba7-32f1b706892f}
CLSIA|{4418dd4d-7265-4c32-bc0a-3fdb3c2da938}
CLSIA|{ef86873f-04c2-4a95-a373-5703c08efc7b}
IEZON|*.offshoreclicks.com
IEZON|.teensguru.com
IEZON|xxxtoolbar.com
FILEN|best.exe
NEWPR|2848|Yapbrowser
PRCAT|5
DIREC|%allusersprofile%\Start Menu\Programs\YapBrowser
DIREC|%programfiles%\yapbrowser
UINST|yapbrowser
FILEN|%allusersprofile%\Desktop\YapBrowser.lnk
FILEN|%allusersprofile%\Start Menu\Programs\Startup\YapBrowser.lnk
NEWPR|3056|Yazzle Cowabanga
PRCAT|5
DIREC|%ProgramFiles%\Cowabanga\
RKSOF|Cowabanga
UINST|Cowabanga
UINST|Yazzle1264Oin
FILEN|%USERPROFILE%\Start Menu\Programs\Games\Cowabanga.lnk
FILEN|yazzle1119oinuninstaller.exe
FILEN|yazzle1264oinadmin.exe
FILEN|yazzle1264oinuninstaller.exe
FILEN|yazzlebundle-1264.exe
NEWPR|2897|Yazzle Snow Ball War
PRCAT|5
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Yazzle Snowball Wars
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yazzle Snowball Wars
DIREC|%programfiles%\snowball wars
DIREC|%ProgramFiles%\Yazzle Snowball Wars\
DIREC|%userprofile%\Start Menu\Programs\Yazzle Snowball Wars\
AUTST|Snowball Wars
RKSOF|Yazzle Snowball Wars
UINST|Snowball Wars
UINST|Yazzle Snowball Wars
NEWPR|2355|Yazzle Sudoku
PRCAT|5
CLSID|{665ac8e7-8b9b-40d9-a24d-c134052b6168}
CLSID|{8b7cd17e-428b-4ee7-bbcd-21875fa05d7f}
CLSID|{907977fb-8835-483f-9979-ae3101dd3d17}
CLSID|{95b10d86-f27f-40b6-9a57-53db278546d0}
CLSID|{95c2547b-0785-4278-9aea-ce65d78d853d}
REGKE|HKEY_CLASSES_ROOT\YazzleSudokuGame
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Yazzle Sudoku
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\YazzleSudokuGame
DIREC|%ProgramFiles%\Yazzle Sudoku\
DIREC|%userprofile%\Start Menu\Programs\Yazzle Sudoku\
AUTST|FT_SilentSudokuInstaller.exe
AUTST|ms05447449-1862
AUTST|sys02862447449-1
CLASS|.sdu
CLASS|YazzleSudokuGame
RKSOF|Tanw
RKSOF|Yazzle Sudoku
UINST|Y1123Oin
UINST|Y1304Oin
UINST|Yazzle1162Oin
UINST|Yazzle1438Oin
UINST|Yazzle1452Oin
UINST|YazzleSudoku
FILEN|ageu_silentsudokuinstaller.exe
FILEN|ageu_sudokuinstaller.exe
FILEN|ft_silentsudokuinstaller.exe
FILEN|gs_silentsudokuinstaller.exe
FILEN|yazzle1119oinadmin.exe
FILEN|yazzlebundle-1119.exe
FILEN|yazzlebundle-1304.exe
FILEN|yazzlebundle-1438.exe
FILEN|yazzlebundle-1452.exe
NEWPR|1285|YellowPages
PRCAT|5
CLSID|{47fe5d70-9aa2-40f1-9c6b-12a255f085ea}
CLSID|{49f2248d-1734-4b0f-a7b8-542e526ee07c}
CLSID|{679695bc-a811-4a9d-8cdf-ba8c795f261a}
CLSID|{d797ad6c-6447-4db4-91d0-090344408e72}
CLASS|YellowPages.YellowBar
NEWPR|2395|Youcouldwinthis
PRCAT|5
CLSID|{d7950ab4-67f5-458e-a37d-9f2de7f250ac}
DIREC|%ProgramFiles%\YOUCOULDWINTHIS\
CLASS|AdCom.AdCom
UINST|{534902F9-3758-4304-BFC0-24800B4E5FB9}
NEWPR|3063|Your Screen
PRCAT|5
DIREC|%programfiles%\freeze.com
DIREC|%programfiles%\yourscreen
CLASS|Freeze.DesktopManager.BrowserHelper.DLL
CLASS|FreezeDesktopManagerBrowserHel.Browse
CLASS|FreezeDesktopManagerBrowserHel.BrowserH
RKSOF|Freeze
UINST|Living Waterfalls Wallpaper #1
UINST|YourScreen
FILEN|waterfalls1awfree.exe
FILEN|yourscreen_4_pch.exe
NEWPR|974|YourSiteBar
PRCAT|5
CLSID|{03b800f9-2536-4441-8cda-2a3e6d15b4f8}
CLSIA|{42f2c9ba-614f-47c0-b3e3-ecfd34eed658}
CLSID|{4ee12b71-aa5e-45ec-8666-2db3ad3fdf44}
CLSIA|{771a1334-6b08-4a6b-aedc-cf994ba2cebe}
CLSID|{bf06da8e-2beb-4816-9bbd-f7625246e245}
CLSID|{db447818-96b4-40df-8a55-720da496f514}
CLSID|{dfbcc1eb-b149-487e-80c1-cc1562021542}
DIREC|%programfiles%\YourSiteBar
DIREC|%programfiles%\YourSitetoolbar
CLASS|Ysb.YsbObj
CLASS|YSBactivex.Installer
RKSOF|YourSiteBar
UINST|YourSiteBar
FILEN|yoursitebar.exe
NEWPR|795|Zamingo
PRCAT|5
AUTST|Adstartup
FILEN|adstartup.exe
FILEN|ieenhancer.dll
NEWPR|1987|Zango
PRCAT|5
CLSIA|{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8}
CLSIA|{99410cde-6f16-42ce-9d49-3807f78f0287}
CLSID|{d28cd14c-50be-4cfa-951e-b37f25da3472}
CLSIA|{deceaaa2-370a-49bb-9362-68c3a58ddc62}
CLSID|{ea0d26bd-9029-431a-86e0-83152d67828a}
DIREC|%allusersprofile%\Start Menu\Programs\Zango Games\
DIREC|%programfiles%\Zango Games\
DIREC|%programfiles%\ZangoClient\
DIREC|%programfiles%\zango\
DIREC|%userprofile%\Start Menu\Programs\Zango Games\
DIREC|%userprofile%\Start Menu\Programs\Zango\
CLASS|ncmyb.SABHO
CLASS|saix.installercaller
RKSOF|zanu
UINST|zanu
FILEN|%programfiles%\zango\zango.exe
FILEN|zango.exe
FILEN|zangoinstaller.dll
FILEN|zangoinstaller.exe
FILEN|zangolib.dll
FILEN|zangomuncher.exe
FILEN|zanuhook.dll
NEWPR|2373|Zango Grab&Burn
PRCAT|5
DIREC|%programfiles%\Zango Applications\
DIREC|%userprofile%\Start Menu\Programs\Zango Applications\
RKSOF|www.zango
UINST|Zango Grab & Burn
UINST|Zango Grab & Burn DisplayIcon
FILEN|%userprofile%\desktop\Zango Grab & Burn.lnk
NEWPR|2176|Zango Messenger
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\Zango
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\Zango Applications
DIREC|%programfiles%\Zango Applications
AUTST|zanu
RKSOF|Zango Messenger
UINST|Zango Messenger
NEWPR|2568|Zango Times
PRCAT|5
DIREC|%appdata%\Zango TvTimes\
UINST|Zango TV Times
NEWPR|2298|Zango Toolbar
PRCAT|5
CLSID|{01bf19c2-59d3-43e9-a2cc-c2d62d8878d3}
CLSID|{f1f040d5-e8f8-4680-b101-9334e9773841}
REGKE|HKEY_CLASSES_ROOT\AppID\ZangoToolbar.DLL
DIREC|%allusersprofile%\Start Menu\Programs\Zango\
DIREC|%programfiles%\Zango Programs\
DIREC|%ProgramFiles%\Zango Toolbar\
AUTST|zango
CLASS|ZangoToolbar.DLL
CLASS|ZangoToolbar.ZCToolBand
RKSOF|zango
RKSOF|Zango Programs
UINST|zango
UINST|Zango Toolbar
FILEN|zangohook.dll
FILEN|zangotb.dll
FILEN|zangotbuninstaller.exe
NEWPR|2902|Zango TV
PRCAT|5
CLSID|{5490ef03-553e-42d6-a437-9bfb70c45231}
DIREC|%allusersprofile%\Start Menu\Programs\Zango Programs\
DIREC|%allusersprofile%\Start Menu\Programs\Zango Programs\Zango TV\
DIREC|%ProgramFiles%\Zango Programs\Zango TV\
DIREC|%systemdrive%\WINNT\Installer\{5490EF03-553E-42D6-A437-9BFB70C45231}\
FILEN|%
allusersprofile%\Desktop\Zango TV.lnk
NEWPR|2573|Zango-AirHockey
PRCAT|5
DIREC|%allusersprofile%\Local Settings\Temp\Zango\AirHockey\
DIREC|%allusersprofile%\Start Menu\Programs\Zango Games\Air Hockey\
DIREC|%ProgramFiles%\Zango Games\AirHockey\
RKSOF|MLP\AirHockey
UINST|Air Hockey
NEWPR|2567|Zango-Astrology
PRCAT|5
DIREC|%appdata%\Zango Astrology\
UINST|Zango Astrology
NEWPR|2556|Zango-Checkers
PRCAT|5
NEWPR|2532|Zango-Chess
PRCAT|5
DIREC|%allusersprofile%\Start Menu\Programs\Zango Games\Chess\
DIREC|%ProgramFiles%\Zango Games\Chess\
UINST|Chess
NEWPR|2540|Zango-DavidvsGoliath
PRCAT|5
NEWPR|2577|Zango-Foosball
PRCAT|5
DIREC|%allusersprofile%\Local Settings\Temp\Zango\
DIREC|%allusersprofile%\Start Menu\Programs\Zango Games\Foosball\
DIREC|%ProgramFiles%\Zango Games\Foosball\
RKSOF|Lantern Games\GameRoom\Foosball
UINST|Foosball
NEWPR|2338|Zango-JadeShadow
PRCAT|5
FILEN|jadeshadowinstall.exe
FILEN|jadeshadowsetup.exe
NEWPR|2559|Zango-Libraryoftheages
PRCAT|5
UINST|Library of the Ages
NEWPR|2566|Zango-MovieTimes
PRCAT|5
CLSID|{56f1d444-11bf-4879-a12b-79cf0177f038}
DIREC|%appdata%\Zango MovieTimes\
CLASS|ClientAX.ZangoClientAX
CLASS|zangohook.SABHO
UINST|Zango Movie Times
NEWPR|2570|Zango-Muncher
PRCAT|5
UINST|Zango Muncher
NEWPR|2563|Zango-SecretChamber
PRCAT|5
UINST|Secret Chamber
NEWPR|2558|Zango-Shuffleboard
PRCAT|5
UINST|Shuffle Board
NEWPR|2543|Zango-Solitaire
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\Zango Games\Zango Solitaire\
DIREC|%ProgramFiles%\Zango Games\Zango Solitaire\
UINST|Zango Solitaire
NEWPR|2598|Zango-WallsofJericho
PRCAT|5
UINST|Walls of Jericho
NEWPR|2497|Zango-Windwords
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\Zango Games\Wind Words\
DIREC|%ProgramFiles%\Zango Games\Wind Words\
UINST|Wind Words
NEWPR|1714|ZapSpot
PRCAT|5
DIREC|%APPDATA%\Application Data\ZapSpot\
DIREC|%USERPROFILE%\My Documents\My ZapSpot\
CLASS|ZapSpot.ZML
FILEN|zapspot.exe
NEWPR|2791|Zeno Search Assistant
PRCAT|5
AUTST|BrowserUpdateSched
AUTST|ExploreUpdSched
AUTST|{2F-F8-82-28-ZN}
AUTST|{E4-44-4B-B0-ZN}
UINST|Enhanced Ads by Zeno
UINST|Zeno Search Assistant
FILEN|%userprofile%\Start Menu\Programs\Startup\Zeno.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Startup\Z_Start.lnk
FILEN|%windir%\system32\msnav32.ax
FILEN|dwdsregt.exe
FILEN|nt68rrtc12.sys
FILEN|zicorn001.exe
NEWPR|2359|ZeroPopUp Toolbar
PRCAT|5
DIREC|%programfiles%\ZeroPopupBar\
CLASS|ToolBand.ToolBandObj
UINST|ZeroPopUpBar
NEWPR|957|ZestyFind
PRCAT|5
CLSID|{5cf8a355-f8c6-4883-9c25-49d01a7d25be}
CLSID|{86227d9c-0efe-4f8a-aa55-30386a3f5686}
CLSIA|{a16e6189-a1dd-4696-9806-0324c145d794}
CLSIA|{ca034dcc-a580-4333-b52f-15f98c42e04c}
CLSIA|{fe4bbea8-1efd-4b8a-bd1b-341ccdbeeaa6}
DIREC|%ProgramFiles%\YourSiteBar\
AUTST|Findwavemeetloud
AUTST|gdaj
AUTST|kvern16.dll
AUTST|Trans Comp
AUTST|vernn16.dll
FILEN|%USERPROFILE%\desktop\Cheap Holiday Travel.url
FILEN|%USERPROFILE%\desktop\Free Online Music.url
FILEN|icont.exe
NEWPR|2001|Zeta
PRCAT|5
REGKE|HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZESOFT
REGKE|HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ZESOFT
DIREC|%windir%\system32\jcngn
DIREC|%windir%\system32\omjffbrq
DIREC|%windir%\system32\qkoj
DIREC|%windir%\system32\yjtgnqsu
AUTST|Gmedia2
AUTST|nfxpbvd
AUTST|spiven
FILEN|%windir%\system32\spiven.exe
SERVI|nfxpbvdjcngn
SERVI|Zesoft
NEWPR|3443|Zhong
PRCAT|5
CLSID|{0cb66ba8-5e1f-4963-93d1-e1d6b78fe9a2}
CLSID|{2a0176fe-008b-4706-90f5-bba532a49731}
CLSID|{3ce496d1-1746-41cd-9489-3c0b93df10e2}
CLSID|{42d25f15-cf07-4a72-b191-db0792bf310c}
CLSID|{967a494a-6aec-4555-9caf-fa6eb00acf91}
CLSID|{9692be2f-eb8f-49d9-a11c-c24c1ef734d5}
CLSID|{a8954909-1f0f-41a5-a7fa-3b376d69e226}
CLSID|{d0903a3b-f0ea-434a-9742-98c5335c7946}
NEWPR|692|ZipClix
PRCAT|5
CLSIA|{319a68db-06d0-46da-9f93-a810d5a70836}
CLSID|{bbcd25c8-a31e-4dfb-b204-b54bba477b23}
CLSID|{ec34a4b3-809a-4a71-88d4-55b5183d6041}
DIREC|%programfiles%\zipclix\
CLASS|zipclix
CLASS|zipclixobj.zipclixobj
RKSOF|zipclix
UINST|zipclix
FILEN|zipclix.dll
FILEN|zipclix.exe
NEWPR|921|Zippylookup
PRCAT|5
CLSID|{19e41a2d-bd9d-48bb-9576-27b2cf0877c0}
CLSID|{49256fe8-6394-4ace-939c-22f35ca042ad}
NEWPR|2857|Zone-DL.Plugin
PRCAT|5
CLSIA|{2473bf2d-ca0a-11da-88db-0050bf2938e1}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , dns-look-up.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , netbios-wait.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , netsearchsoft.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.dns-look-up.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.netbios-wait.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.netsearchsoft.com
DIREC|%programfiles%\Download Plugin\
WINDO|windWWAA
WINDO|wwBYAwnd
AUTST|close jump
CLASS|DownloadPlugin.DLPlugin
UINST|Download Plugin (ActiveX)
UINST|Wait long soft
FILEN|axdlplug-1.5.0.0-0281-setup.exe
FILEN|axdlplug-1.5.0.0-147-setup.exe
FILEN|npdlplug-1.5.0.0-147-setup.exe
NEWPR|1757|Zoombar
PRCAT|5
NEWPR|1342|Zserv
PRCAT|5
CLSID|{00000000-c1ec-0345-6ec2-4d0300000000}
NEWPR|2276|ZToolbar
PRCAT|5
CLSID|{a55c3ba7-db1e-4652-867e-055ceafe8018}
CLSID|{ef77d50b-5767-4e0e-a3a4-098670025f1d}
CLSID|{fff5092f-7172-4018-827b-fa5868fb0478}
CLASS|Ztoolbar
CLASS|ZToolbar.activator
CLASS|ZToolbar.ParamWr
CLASS|ZToolbar.StockBar
RKSOF|ZsearchCo
FILEN|%windir%\blank.mht
FILEN|%windir%\system32\ztoolbar.bmp
FILEN|%windir%\system32\ztoolbar.xml
NEWPR|1119|Zuvio
PRCAT|5
CLSID|{30a56549-9d5b-4d34-afa7-440a7f0538a9}
CLSIA|{419cc403-e9fc-4c90-bbe6-c8ea9159e49d}
CLSIA|{ed2e4bb5-60ea-4624-9de2-998e441c699b}
DIREC|%ProgramFiles%\Open Site
AUTST|Open Site
CLASS|OpenSite.opensite_install
UINST|Open Site
FILEN|%systemdrive%\msole32.exe
FILEN|opensite.cab
FILEN|opensite.exe
FILEN|opensite.ocx
NEWPR|1715|ZyncosSpace
PRCAT|5
CLSID|{f0dc0cfe-d11a-489b-84c0-63748afaabf3}
DIREC|%programfiles%\zyncosspace\
AUTST|ZyncosMark
CLASS|CMCTL.CBrowserExt
CLASS|CMCTL.CURLTriggerProxy
RKSOF|Tmsitech
NEWPR|647|764 Dialer
PRCAT|8
NEWPR|956|7AdPower Dialer
PRCAT|8
CLSIA|{00000000-0000-0000-0000-000020030000}
CLSIA|{00000000-0000-0000-0000-000020040000}
CLSIA|{042eea26-2402-4e5a-b5bb-0fb445a5526e}
CLSIA|{0fcd5a05-bcec-4bb1-9ed3-88c289d87abb}
CLSIA|{2517f764-6f60-4add-8fcf-137e5b220ff6}
CLSIA|{261ee805-4893-45a3-8e9e-ad90914cb39a}
CLSIA|{35f59c80-c1f2-4eea-9981-686c7d5a9277}
CLSIA|{3b623d23-2757-4881-a01e-d560ebca5307}
CLSID|{3da4a3a4-06be-49e0-b8ba-03580903122b}
CLSIA|{4208564c-62f0-45e6-87de-0861d11c0613}
CLSIA|{4ae9e3bf-409d-4f61-9804-920968603919}
CLSIA|{4ef86fae-4fda-4b1a-a80f-811e0a5da08a}
CLSID|{5d647e9c-6b37-4636-9a78-dadb1eb93bdf}
CLSIA|{60efc337-15c2-4369-b2a0-3429b071d8b8}
CLSIA|{683dff0f-331f-44d2-b69b-46d7bfb58f32}
CLSIA|{706f3805-27d7-478d-80e5-e25d2bb030b3}
CLSIA|{8701e3b9-dc63-440b-83a1-80f27a4fcafa}
CLSIA|{8bea0789-fe58-4753-8a75-432fcd1a5705}
CLSIA|{970bf476-3cf2-4572-9ef9-4479e1591db8}
CLSIA|{9e98e84c-79e1-49c3-82eb-798fcd552efb}
CLSID|{ac86f549-28a6-4ac8-9c2c-0d52b4b1f5ec}
CLSIA|{ad0b8220-7da4-4c0a-8532-b25a9f631d3d}
CLSIA|{b1b7606a-d7b9-42a8-afa2-476308413211}
CLSIA|{bd092cd7-aa66-4ff6-8ce1-d4e01489ed2b}
CLSIA|{c7384a94-12ab-4798-9a63-67a9b24c993d}
CLSIA|{cdcbe0f1-d13a-4f86-a963-3a272d3aba7e}
CLSIA|{f1051f05-fbfa-48bd-8e45-f5d3bdc45d3d}
CLSIA|{f164ece9-e6df-4085-961c-083bd1809319}
CLSID|{f43e6264-7da7-45af-a90d-75534f0c6754}
CLSIA|{f9deab0b-ff3e-4d99-8698-9b535d164256}
CLSIA|{ffff0001-0002-101a-a3c9-08002b2f49fb}
CLSIA|{ffff0021-0002-101a-a3c9-08002b2f49fb}
AUTST|AdPopup
AUTST|AdUpdater
CLASS|VacPro.internazionale_ver11
CLASS|Vacpro.netherland_ver2
FILEN|internazionale_ver15.cab
NEWPR|2585|Absolu-trans
PRCAT|8
FILEN|absolu-trans.exe
NEWPR|583|AccessPlugin
PRCAT|8
CLSIA|{034cc2dc-3245-4b26-b5c7-7b8777739cb7}
CLSIA|{2b3ac84b-3128-45b4-bb8d-6cc9a42d24ec}
CLSIA|{42f2d240-b23c-11d6-8c73-70a05dc10000}
CLSIA|{d8efadf1-9009-11d6-8c73-608c5dc19089}
REGKE|HKEY_CLASSES_ROOT\AppID\exengd.EXE
CLASS|Exengd.DialerCon
RKSOF|DCon
RKSOF|webdialer
NEWPR|648|Aconti
PRCAT|8
CLSIA|{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}
CLSIA|{7589eee6-e336-11d4-8a7e-ee1d971d9b47}
AUTST|runwin32
CLASS|AcontiXControl
RKSOF|ALifestyle
FILEN|int179663.exe
NEWPR|2167|Active-X Dialer
PRCAT|8
CLSIA|{0f7bd988-96a9-4505-9997-19011055f07c}
CLSIA|{33bcb2bb-173d-163b-779b-33c13379504c}
CLSIA|{62c9173e-c4c3-43b9-82f2-3ddd51663b00}
CLSIA|{7dbfda8e-d33b-11d4-9269-00600868e56e}
CLSIA|{84b40160-54e0-4d2f-ac18-a6d31a9ac732}
CLSIA|{86eef11e-ff16-48ce-b1a2-474b663041a9}
CLSIA|{c56ce781-a6fc-4706-8b32-6eb4622155df}
CLSID|{cfbc1c51-d33c-11d4-9269-00600868e56e}
FILEN|gdnus208.exe
NEWPR|2575|Adh1_sexarea
PRCAT|8
DIREC|%programfiles%\montorgueil
DIREC|%userprofile%\Start Menu\Programs\HOT Dialer\
FILEN|%userprofile%\Start Menu\Latinas.lnk
NEWPR|1100|Adpower.b
PRCAT|8
CLSIA|{3e339d3c-4b12-4e8c-a529-9cc4beeafd4f}
CLSID|{7b6ff147-4e5a-4a2f-8789-84efc132849d}
CLSIA|{84bf9dc5-7bc8-4efd-
85b3-489c714f4fd1}
CLSIA|{91b9979b-c663-43a0-855e-df04025eb0a2}
CLSIA|{9ae283a5-df43-4c83-b6aa-7ebdbdb0204a}
CLSID|{e4870a7b-6c2f-42b9-9938-f6d729afc493}
CLSIA|{fbc59f54-80a2-4df5-a0ad-b2d3221c8b32}
RKSOF|ADPower
NEWPR|646|Adult Chat Dialer
PRCAT|8
CLSID|{022850cb-74fd-486d-8b1c-573ecfd599ad}
CLSIA|{2c1651ef-8827-11d6-91a2-00e02964e8e3}
CLSIA|{469843dd-ebb3-4661-b0a6-e6fe590240c9}
CLSIA|{6986a6cf-9d58-11d6-91c2-00e02964e8e3}
CLSIA|{8522f9b3-38c5-4aa4-ae40-7401f1bbc898}
CLSIA|{9dbafccf-592f-ffff-ffff-00608cec297c}
CLSID|{b5dd9a64-5c4b-4a48-be56-97c1a8f85708}
CLSIA|{ffff0017-0001-101a-a3c9-08002b2f49fb}
DIREC|%programfiles%\nog\
AUTST|addot.exe
AUTST|Lisa
AUTST|MSStartOptimizer
AUTST|RegCompres
AUTST|tibs3
CLASS|.htnw
CLASS|htnw File
RKSOF|nog
RKSOF|Pinfo
UINST|Lisa
FILEN|adult_chat.exe
FILEN|tibs3.exe
NEWPR|1971|Adult Dialer
PRCAT|8
CLSIA|{8f24de00-0d66-4f93-9405-3f21e97aee99}
CLSIA|{94118c19-b178-4e43-bbe8-0efdbb391bdb}
AUTST|HotSexy_Now
FILEN|esbadultinstaller.ocx
NEWPR|2418|Adult.LSDIALER
PRCAT|8
FILEN|%Systemdrive%\ecommerce\dialer.ini
NEWPR|1151|Adultoweb Dialer
PRCAT|8
CLSIA|{067d7797-04fc-42b1-92db-81fc6cd318fd}
CLSIA|{23273a1c-c870-43c4-a3e3-67dc98630ac6}
CLSIA|{a45f39dc-3608-4237-8f0e-139f1bc49464}
CLSIA|{c771b05e-e725-4516-97a5-4ce5eb163cfb}
DIREC|%ProgramFiles%\fist\
AUTST|NsUpdate
RKSOF|GlobalCS
FILEN|%UserProfile%\Desktop\fist.LNK
FILEN|%UserProfile%\Start Menu\Programs\fist.LNK
NEWPR|1228|All-In-One Telcom
PRCAT|8
CLSID|{da9a0b0f-9b7b-11d3-b8a4-00c04f79641c}
CLSID|{da9a0b1d-9b7b-11d3-b8a4-00c04f79641c}
CLSID|{da9a0b1f-9b7b-11d3-b8a4-00c04f79641c}
CLASS|hadate file
CLASS|nsupdatelite.nsupdatelitectrl
RKSOF|hotactiondating
UINST|hotactiondating
NEWPR|2578|Andlotsmore.com dialer
PRCAT|8
NEWPR|820|babetv
PRCAT|8
CLSIA|{30ce93ae-4987-483c-9abe-f2bd5301ab70}
NEWPR|2588|BlondeSalope
PRCAT|8
NEWPR|779|BTV Dialer
PRCAT|8
DIREC|%ProgramFiles%\BTV\
DIREC|%ProgramFiles%\Common Files\midaddle\
DIREC|%programfiles%\diallerprogram\
AUTST|breg
NEWPR|2615|CAX Dialer
PRCAT|8
CLSIA|{2048b51e-8d74-4762-82ce-b48cf545eeea}
NEWPR|2579|CazzoCulo
PRCAT|8
NEWPR|2159|Central-24 Dialer
PRCAT|8
CLSID|{000000aa-abba-0704-0b53-2c8830e9faec}
CLSID|{0f4a7b40-a295-11cf-a3a9-00a0c9034920}
CLSID|{c60bc918-abba-0704-0b53-2c8830e9faec}
CLSIA|{dcf96da0-ed33-40ff-b83e-ab7011c2ba7e}
NEWPR|614|CrossKirk
PRCAT|8
CLSID|{0d639e64-5c31-4313-b62a-1b4d99e2f284}
CLSID|{3cd945a2-e413-4956-b9d8-a67fb6a7cb66}
CLSID|{9d6addbf-8227-4d36-ae46-116afbdafca0}
CLSID|{d24a1963-9951-4153-a340-6648759eb77d}
FILEN|crosskirk.cab
NEWPR|2593|Cuty girls
PRCAT|8
CLASS|XEng019.XEng019Ctl
NEWPR|2590|Cytainment
PRCAT|8
CLSIA|{00000000-abba-0704-0b53-2c8830e9faec}
CLASS| IELoaderCtl.IELoaderCtl
NEWPR|2251|Dataline Dialer
PRCAT|8
FILEN|dbn1742.exe
NEWPR|1968|Dialer-S
PRCAT|8
CLSID|{6986a6c2-9d58-11d6-91c2-00e02964e8e3}
CLASS|Pagomaster.IntPagomaster
FILEN|pagomaster.dll
NEWPR|1303|dialer-shop
PRCAT|8
CLSID|{6814a9ef-fbf1-46b2-a46e-56b401079c26}
CLSIA|{9d0a9d98-5221-430a-a02d-76f0827c82d1}
CLSIA|{d7b59209-0ed9-4986-bd4a-527be836c6b2}
NEWPR|2258|Dialer.ASDPlugin
PRCAT|8
AUTST|ASDPLUGIN
RKSOF|ASDPLUGIN
FILEN|%USERPROFILE%\Desktop\Launch DerBiz.com.lnk
FILEN|%USERPROFILE%\Desktop\Launch globalEaccess.lnk
FILEN|%userprofile%\Desktop\SurfYa.com.lnk
FILEN|%USERPROFILE%\Start Menu\Launch DerBiz.com.lnk
FILEN|%USERPROFILE%\Start Menu\Launch globalEaccess.lnk
FILEN|%userprofile%\Start Menu\SurfYa.com.lnk
FILEN|%USERPROFILE%\Start Menu\Uninstall Launch DerBiz.com.lnk
FILEN|%USERPROFILE%\Start Menu\Uninstall Launch globalEaccess.lnk
FILEN|%userprofile%\Start Menu\Uninstall SurfYa.com.lnk
FILEN|%Windir%\system32\dsldbaccess.exe
FILEN|%Windir%\system32\Geaccess.exe
NEWPR|2876|Dialer.Baj
PRCAT|8
NEWPR|2727|Dialer.BNI
PRCAT|8
NEWPR|1840|Dialer.Intexusdial
PRCAT|8
DIREC|%userprofile%\Start Menu\Programs\- tattooworld -
DIREC|%userprofile%\Start Menu\Programs\- tbuyit -
DIREC|%userprofile%\Start Menu\Programs\- Template-Tempel -
DIREC|%userprofile%\Start Menu\Programs\- testedich -
DIREC|%userprofile%\Start Menu\Programs\- Textfun.de - Witze und Sprueche -
DIREC|%userprofile%\Start Menu\Programs\- TheHentai.NET Hentai Erotik
DIREC|%userprofile%\Start Menu\Programs\- TheHentai.NET Hentai Erotik -
DIREC|%userprofile%\Start Menu\Programs\- Tierbabys -
DIREC|%userprofile%\Start Menu\Programs\- Tierheime -
DIREC|%userprofile%\Start Menu\Programs\- Toprezpte24 -
DIREC|%userprofile%\Start Menu\Programs\- Trilian-de -
DIREC|%userprofile%\Start Menu\Programs\- Tuerkei -
DIREC|%userprofile%\Start Menu\Programs\- TURKGAYS -
DIREC|%userprofile%\Start Menu\Programs\- UmsatzSteigern.de -
DIREC|%userprofile%\Start Menu\Programs\- Vornamen-Fundus -
DIREC|%userprofile%\Start Menu\Programs\- Wetter-Basis -
DIREC|%userprofile%\Start Menu\Programs\- witzealarm -
DIREC|%userprofile%\Start Menu\Programs\- Wohnung -
DIREC|%userprofile%\Start Menu\Programs\- XP-Antispy.de -
RKSOF|Intexus
RKSOF|IntexusDial
UINST|1md.de
FILEN|%userprofile%\Desktop\1md.de.lnk
FILEN|%userprofile%\Desktop\Anti-Report anti-report.lnk
FILEN|%userprofile%\Desktop\Counter.de counterde.lnk
FILEN|%userprofile%\Desktop\Fahrschule fahrschule.lnk
FILEN|%userprofile%\Desktop\GifProfi gifprofi.lnk
FILEN|%userprofile%\Desktop\gifsworld gifsworld.lnk
FILEN|%userprofile%\Desktop\Girlscam girlscam.lnk
FILEN|%userprofile%\Desktop\GrussProfi grussprofi.lnk
FILEN|%userprofile%\Desktop\HENTOON.DE hentai-de.lnk
FILEN|%userprofile%\Desktop\IQ Welt iqwelt.lnk
FILEN|%userprofile%\Desktop\iqtest iqtest.lnk
FILEN|%userprofile%\Desktop\lebenslauf.de lebenslauf-de.lnk
FILEN|%userprofile%\Desktop\Manga6.de manga6-de.lnk
FILEN|%userprofile%\Desktop\Megastars megastars.lnk
FILEN|%userprofile%\Desktop\Meine Seite meineseite.lnk
FILEN|%userprofile%\Desktop\Monster Vorlagen monstervorlagen.lnk
FILEN|%userprofile%\Desktop\MP3-Legal mp3-legal.lnk
FILEN|%userprofile%\Desktop\Neandertaler neandertaler.lnk
FILEN|%userprofile%\Desktop\neueinrichten.de neueinrichten-de.lnk
FILEN|%userprofile%\Desktop\Online Diaet onlinediaet.lnk
FILEN|%userprofile%\Desktop\Referate referate.lnk
FILEN|%userprofile%\Desktop\ReporteMafia.de reportemafia-de.lnk
FILEN|%userprofile%\Desktop\Reptilien.AG reptilien-ag.lnk
FILEN|%userprofile%\Desktop\Rezepte.AG rezepte-ag.lnk
FILEN|%userprofile%\Desktop\Rezeptsammlung.com rezeptsammlung-com.lnk
FILEN|%userprofile%\Desktop\Routenplaner Profi routenplanerprofi.lnk
FILEN|%userprofile%\Desktop\Sagen sagen.lnk
FILEN|%userprofile%\Desktop\schei1 schei1.lnk
FILEN|%userprofile%\Desktop\Schoener werden schoenerwerden.lnk
FILEN|%userprofile%\Desktop\schulstadt schulstadt.lnk
FILEN|%userprofile%\Desktop\sexworld sexworld.lnk
FILEN|%userprofile%\Desktop\Smilie-Fabrik smilie-fabrik.lnk
FILEN|%userprofile%\Desktop\Spasspilot.de spasspilot-de.lnk
FILEN|%userprofile%\Desktop\Spieleindex spieleindex.lnk
FILEN|%userprofile%\Desktop\Sprueche.de sprueche-de.lnk
FILEN|%userprofile%\Desktop\Supergames supergames.lnk
FILEN|%userprofile%\Desktop\Taroskop.de taroskop-de.lnk
FILEN|%userprofile%\Desktop\Tattoo Mania tattoomania.lnk
FILEN|%userprofile%\Desktop\tattoopalace tattoopalace.lnk
FILEN|%userprofile%\Desktop\tbuyit tbuyit.lnk
FILEN|%userprofile%\Desktop\Template-Tempel template-tempel.lnk
FILEN|%userprofile%\Desktop\testedich testedich.lnk
FILEN|%userprofile%\Desktop\Textfun.de - Witze und Sprueche textfun-de.lnk
FILEN|%userprofile%\Desktop\TheHentai.NET Hentai Erotik thehentai-net.lnk
FILEN|%userprofile%\Desktop\Tierbabys tierbabys.lnk
FILEN|%userprofile%\Desktop\Toprezpte24 toprezpte24.lnk
FILEN|%userprofile%\Desktop\Trilian-de trilian-de.lnk
FILEN|%userprofile%\Desktop\Vornamen-Fundus vornamen-fundus.lnk
FILEN|%userprofile%\Desktop\XP-Antispy.de xp-antispy-de.lnk
FILEN|%userprofile%\Recent\Intexusdial.cc.lnk
FILEN|%userprofile%\Start Menu\Programs\- GifProfi -\GifProfi gifprofi.lnk
FILEN|%userprofile%\Start Menu\Programs\- gifsworld -\gifsworld gifsworld.lnk
FILEN|%userprofile%\Start Menu\Programs\- Girlscam -\Girlscam girlscam.lnk
FILEN|%userprofile%\Start Menu\Programs\- Megastars -\Megastars megastars.lnk
FILEN|%userprofile%\Start Menu\Programs\- Meine Seite -\Meine Seite meineseite.lnk
FILEN|%userprofile%\Start Menu\Programs\- Monster Vorlagen -\Monster Vorlagen monstervorlagen.lnk
FILEN|%userprofile%\Start Menu\Programs\- Neandertaler -\Neandertaler neandertaler.lnk
FILEN|%userprofile%\Start Menu\Programs\- neueinrichten.de -\neueinrichten.de neueinrichten-de.lnk
FILEN|%userprofile%\Start Menu\Programs\- Online Diaet -\Online Diaet onlinediaet.lnk
FILEN|%userprofile%\Start Menu\Programs\- Referate -\Referate referate.lnk
FILEN|%userprofile%\Start Menu\Programs\- ReporteMafia.de -\ReporteMafia.de reportemafia-de.lnk
FILEN|%userprofile%\Start Menu\Programs\- Reptilien.AG -\Reptilien.AG reptilien-ag.lnk
FILEN|%userprofile%\Start Menu\Programs\- Rezepte.AG -\Rezepte.AG rezepte-ag.lnk
FILEN|%userprofile%\Start Menu\Programs\- Rezeptsammlung.com -\Rezeptsammlung.com rezeptsammlung-com.lnk
FILEN|%userprofile%\Start Menu\Programs\- sexworld -\sexworld sexworld.ln
FILEN|%userprofile%\Start Menu\Programs\- sharing.ag -\sharing.ag share-dialer.lnk
FILEN|%userprofile%\Start Menu\Programs\- Smiley Castle -\Smiley Castle smileycastle.lnk
FILEN|%userprofile%\Start Menu\Programs\- TheHentai.NET Hentai Erotik -\TheHentai.NET Hentai Erotik thehentai-net.lnk
FILEN|2da45.exe
FILEN|alternativ-heilung.com ahm-10056.lnk
FILEN|beauty[schoenerwerden,1].exe
FILEN|bpmk.dat
FILEN|cocktails[ccp-10097,de].exe
FILEN|gifsworld[gwd-10927,de].exe
FILEN|hausaufgaben[hun-10002,de].exe
FILEN|hausaufgaben[hun-10222,de].exe
FILEN|horoskop_erstellen[aie-10070,de].exe
FILEN|lehrstellen[lhs-10004,de].exe
FILEN|liebesbriefe[lbi-10023,de,start].exe
FILEN|pflanzen[pla-10006,de].exe
FILEN|routenplanerag.exe
FILEN|sagen.exe
FILEN|satanismus.exe
FILEN|satfrequenzen.exe
FILEN|scheisse[schei1,1].exe
FILEN|schulstadt-1.exe
FILEN|schulstadt-2.exe
FILEN|schulstadt-3.exe
FILEN|schulstadt-4.exe
FILEN|schulstadt-5.exe
FILEN|schulstadt-6.exe
FILEN|schulstadt-7.exe
FILEN|schulstadt.exe
FILEN|schwanger.exe
FILEN|setup(1-1md-0-0-,us)-1.exe
FILEN|sexworld[sexworld,1].exe
FILEN|sharing-ag-1.exe
FILEN|sharing-ag.exe
FILEN|slowenien.de.exe
FILEN|smiley[smileycastle,1].exe
FILEN|smiley[syc-10008,1].exe
FILEN|smilie-fabrik.exe
FILEN|sms-stadt-1.exe
FILEN|sms-stadt-2.exe
FILEN|sms-stadt-3.exe
FILEN|sms-stadt.exe
FILEN|sms-tool.exe
FILEN|songtexte[sgx-10001,1].exe
FILEN|songtextzone-1.exe
FILEN|songtextzone-2.exe
FILEN|songtextzone-4.exe
FILEN|spass4u[s4e-10020,1].exe
FILEN|spasspilot-1.exe
FILEN|spicktricks[ree-10323,de].exe
FILEN|spieledownload[ssg-10001,1,a63e].exe
FILEN|spieleindex[spieleindex,1].exe
FILEN|spiele_runterladen[geg-10066,1].exe
FILEN|sprueche.exe
FILEN|stammbaum.de.exe
FILEN|starfuck.exe
FILEN|stars-nackt.exe
FILEN|sternzeichen[szn-10011,de].exe
FILEN|straflos[anti-report,1].exe
FILEN|suchmaschinen-1.exe
FILEN|supergames[supergames,1].exe
FILEN|taroskop.exe
FILEN|tattoo-1.exe
FILEN|tattoo-2.exe
FILEN|tattoopalace-11.exe
FILEN|tattoos[tod-10109,de].exe
FILEN|tattoos[tod-10133,1].exe
FILEN|tattoovorlagen-de[toe-10362,1]-2.exe
FILEN|tattoo[tattoomania,1].exe
FILEN|tattoo[toe-10082,1].exe
FILEN|template-tempel.exe
FILEN|tests[iqwelt,1].exe
FILEN|test[teh-10116,de,start4].exe
FILEN|tierbabys[tierbabys,1].exe
FILEN|toprezept.exe
FILEN|trilian[trilian-de,1].exe
FILEN|tuerkei.exe
FILEN|turkgays[tks-10001,1].exe
FILEN|umsatzsteigern[uee-10001,1].exe
FILEN|valueradio-1.exe
FILEN|vornamen.exe
FILEN|vornamen[vnf-10049,1].exe
FILEN|vornamen[vnf-10103,1].exe
FILEN|wetter-basis-1.exe
FILEN|wetter-basis.exe
FILEN|witzealarm.exe
FILEN|witze[counterde,1].exe
FILEN|wohnung.exe
NEWPR|2281|Dialer.ks
PRCAT|8
CLSID|{3eb94323-0856-4479-aa22-d81bbfeea91e}
CLSID|{6bc36767-3fcc-4948-8a13-703f887a3e87}
CLSIA|{e53458d2-5a83-4bd1-8de2-eeebe73bab49}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ccaccess.dll
CLASS|Ccaccess.CheckControl
NEWPR|2714|Dialer.Maxd
PRCAT|8
FILEN|maxd641.exe
NEWPR|2119|Dialer.Mostrar
PRCAT|8
CLSID|{095c0db4-fea6-440e-8dfc-00fc53ac827d}
CLSID|{4fc63700-2093-4ad2-8d37-3b3d86d9c940}
CLSID|{5bf0ce3e-61d2-4a7b-baa3-0c4667a9563d}
CLSIA|{88c51e90-8e9c-4c96-8a45-574d88b63faf}
CLSIA|{ffff0003-0001-101a-a3c9-08002b23e0cc}
CLSIA|{ffff0003-0001-101a-a3c9-08002b23e0cd}
REGKE|HKEY_CURRENT_USER\PTPSA32.PTPSAWeb
AUTST|Dialer
CLASS|PTPSA32.PTPSAWeb
FILEN|%windir%\Downloaded Program Files\msa64chk.inf
NEWPR|3532|Dialer.Qi
PRCAT|8
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Emitt
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform , ADVPLUGIN|K115|165|S-866237264|dialno
AUTST|auoie
IEZON|nodialup.name
IEZON|whatsnew.name
FILEN|syslcznp.exe
NEWPR|2609|Dialer.Sfonditalia
PRCAT|8
IEZON|realarea.biz
NEWPR|2877|Dialer.XD
PRCAT|8
NEWPR|2557|DialerActiveX
PRCAT|8
CLSID|{660b7669-1a16-4864-ac91-8ecbbe7de93f}
CLSID|{8e224ed3-c09f-4ff9-9ace-883d99498f26}
CLSID|{aee9cc65-40f3-4f61-b919-a728bc526d58}
CLSID|{b27bf58e-619c-43f6-8f2a-e4c6428b5245}
CLASS|DIALERACTIVEX.DialeractivexCtrl
NEWPR|406|DialerFactory
PRCAT|8
NEWPR|473|DialerOffline
PRCAT|8
CLSID|{1773b696-b019-4fc1-9eed-b1c7f925f56a}
CLSID|{20270406-63ad-4c7e-ae8d-bb632e508ace}
CLSID|{271d7d74-8e6d-4e6c-86f5-66c064cfb74d}
CLSID|{89161220-a3d9-464f-848c-4ebe0546697d}
CLSID|{a8882720-e26c-4073-8b8a-981d32882af7}
CLSID|{b0acf771-f0f7-461f-bef3-5b1a3ba42f51}
CLSID|{cabd7099-6b04-471d-8371-9fde9c2e6bea}
CLSIA|{ceb29da4-7afa-4f24-b3cd-17351d590df0}
FILEN|dialeroffline.dll
NEWPR|821|DialXS
PRCAT|8
CLSIA|{9b4aa442-9ebf-11d5-8c11-0050da4957f5}
CLASS|DialXS.DialXSCtl
NEWPR|2861|E-nrgyPlus Dialer
PRCAT|8
DIREC|%allusersprofile%\Start Menu\Programs\E-nrgyPlus\
DIREC|%programfiles%\E-nrgyPlus\
AUTST|E-nrgyPlus
NEWPR|2514|Edipole
PRCAT|8
CLASS|WebInstall.WWWInstall
NEWPR|2829|Eocha
PRCAT|8
CLSIA|{2f6c63df-48ad-44c3-a761-7fb53ecf064a}
CLSIA|{3a4dcd02-a451-4799-9e1c-ac0d4f769a97}
CLSIA|{3f5e67e1-81e6-4487-bf6f-07941a080bab}
CLSIA|{3fa96320-481c-4af4-819a-968a6426928e}
CLSIA|{4360e841-fe3e-427f-98dc-7abc8ace6665}
CLSIA|{4d4c0269-8303-4448-80dc-a3de34bc5374}
CLSIA|{5c626a4f-28a7-4a29-9ec8-6be20fc70424}
CLSIA|{72e0f892-b9f1-451d-95a3-2e6c1f45c0dd}
CLSIA|{73b9a791-ba9e-418a-b5a4-948b63be04f7}
CLSID|{8431328a-1050-42a8-a615-809f40d3037d}
CLSID|{8dab5c8c-c784-4651-84f7-b6c9f4eec53d}
CLSIA|{96966b7c-ca72-4928-895b-1c2f0e5302a9}
CLSIA|{9caee012-5dff-11db-8373-b622a1ef5492}
CLSIA|{9f54bf10-c88e-43fd-aa9e-16bf45747c72}
CLSIA|{9f5bb9e1-31ae-4a13-8734-15ced0f60a3d}
CLSIA|{ca654d30-99f2-4dd1-b58c-767e2bb862ff}
CLSIA|{ea5b2f8a-2094-47a1-adc5-373e93eaf936}
CLSIA|{ea8804ce-a2f0-4773-89b8-1e5168a1d8d7}
CLSIA|{eb5cdbc6-dba4-48bc-b888-5e2cff9df3cd}
CLSIA|{f40f43f6-890c-479d-a996-306123662084}
DIREC|%ProgramFiles%\SmilEmail\
AUTST|ciakaisen.exe
AUTST|lateshow.exe
AUTST|MicrosoftFirewall
AUTST|MSGlobal
AUTST|MSMalwareKit
AUTST|SmilEmail
AUTST|StopPhish
AUTST|wke.exe
CLASS|ActiveXCOM.myActiveXCOM
CLASS|XBTB08814.IEToolbar
RKSOF|ADWhere Component
RKSOF|Coprocefalo
RKSOF|XBTB08814
UINST|XBTB08814.XBTB08814Toolbar
FILEN|%USERPROFILE%\My Documents\My Music\PrintHood\Canon BJC su Giorgia.lnk
FILEN|%USERPROFILE%\My Documents\My Music\The Clash.lnk
FILEN|%USERPROFILE%\Start Menu\messaggio3.exe
FILEN|%USERPROFILE%\Start Menu\Vocabolario.lnk
IEZON|cds.zangocash.com
IEZON|ciritorno.biz
IEZON|content.licenseacquisition.org
IEZON|cywanstorage.biz
IEZON|defaultbar.com
IEZON|licenseacquisition.org
IEZON|melagodo.biz
IEZON|pergentina.biz
IEZON|playmore.biz
IEZON|preferiti-windows.com
IEZON|static.zangocash.com
IEZON|terzodesiderio.biz
IEZON|www.acquadirose.com
IEZON|www.ciritorno.biz
IEZON|www.defaultbar.com
IEZON|www.forteforte.com
IEZON|www.melagodo.biz
IEZON|www.nanobyte.biz
IEZON|www.pergentina.biz
IEZON|www.phishingfix.biz
IEZON|www.playmore.biz
IEZON|www.popup-freesex-adv.biz
IEZON|www.preferiti-windows.com
IEZON|www.ricercadoppia.com
IEZON|www.scalalap.com
IEZON|www.sextriere.com
IEZON|www.smilemail.biz
IEZON|www.super-videochat-community.biz
IEZON|www.terzodesiderio.biz
IEZON|www.tuttaqualita.com
IEZON|www.umts-gprs-mondo-telefonino-cellulare.biz
IEZON|www.virgilio.in
IEZON|www.what-you-want.biz
NEWPR|2671|Eroskop Dialer
PRCAT|8
AUTST|AntyVirKS
NEWPR|784|EroticAccess
PRCAT|8
CLSIA|{1230cb21-c88d-11cf-b347-000000000000}
CLSIA|{73f0fd85-bd47-4a95-86d1-de38860462c1}
NEWPR|2402|FairTale
PRCAT|8
CLSID|{adb5c6a6-4595-4038-859b-d213969892a3}
CLSID|{e2bba7ac-2347-4761-af7a-0dca61355d53}
CLSID|{e5502c44-565e-4897-819f-c6abae1f89fb}
DIREC|%systemdrive%\fairtale\
CLASS|.ft0
CLASS|Fairtale
CLASS|fairtale.Class1
NEWPR|1798|FairyTale
PRCAT|8
CLSIA|{940ec490-8c20-4360-a725-1f44984933df}
CLSIA|{99e79790-2b09-11d6-8c73-0800460222f0}
NEWPR|2582|FanAlizee
PRCAT|8
NEWPR|2755|FanNolwenn
PRCAT|8
FILEN|%USERPROFILE%\Desktop\FanNolwenn.lnk
FILEN|%USERPROFILE%\Start Menu\FanNolwenn.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\HOT Dialer\FanNolwenn.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\HOT Dialer\Uninstall FanNolwenn.lnk
NEWPR|2591|FanSalma
PRCAT|8
NEWPR|788|FreeLoad
PRCAT|8
NEWPR|2528|Fundial
PRCAT|8
CLSID|{1f20cf42-b381-4181-8c2a-a389b1022e6e}
CLSID|{703e919d-28c9-4491-8d01-8964e47bbbba}
DIREC|%SystemDrive%\dialerfun\
CLASS|Dialer.Class1
NEWPR|2475|Gamesplayground
PRCAT|8
CLSIA|{fde6b956-b80a-4578-9a10-4c24609412f1}
NEWPR|679|GlobalDialer
PRCAT|8
CLSIA|{05d087e7-51bd-3f5b-7bb5-0c6a120fc11a}
CLSIA|{11111111-1111-1111-1111-511111193457}
CLSIA|{11111111-1111-1111-1111-511111193458}
CLSIA|{11111111-1111-1111-1111-611111193457}
CLSIA|{11111111-1111-1111-1111-611111193458}
CLSIA|{11111111-1111-1111-1114-511155593469}
CLSID|{12c94089-40ef-4885-860a-6cdd3e138a20}
CLSIA|{22222222-2222-2222-4444-566661888858}
CLSIA|{23232323-2323-2323-2323-232323231122}
CLSIA|{23232323-2323-2323-2323-232323291122}
CLSIA|{2dc2b96e-1748-11d5-94e4-006008a4ed7f}
CLSIA|{38545c2a-03cd-42c3-bc62-c537a6d5a8f6}
CLSIA|{413a0886-cbc2-4cbe-bbc7-3b423eb15383}
CLSID|{5d945e9a-dc10-4670-83eb-99daa616628a}
CLSIA|{5f944a91-2888-1cef-ffff-7b632dba7c98}
LSIA|{6a5081c6-d0f7-5f22-467f-40610638bfca}
CLSIA|{753c42af-4e2e-5334-f69c-45732649b667}
CLSIA|{7cd66bd1-e395-0425-146c-46cd022dc162}
CLSIA|{861fda2a-2b57-4bda-8b8b-305c9d5d8604}
CLSIA|{97b79133-88f0-45f0-8d57-0f2ef27d9c66}
CLSIA|{b3aa2f6b-6baf-11d3-ba05-00c0f0322972}
CLSIA|{b94b4225-e02e-4d3f-badb-026f1e2f3ad7}
CLSIA|{d22ac3ef-b7d8-11d5-a281-005056bf0101}
CLSIA|{d52d92f2-3650-439c-aa18-03ee4f6859de}
CLSIA|{deda29ca-3653-456e-b4c9-63a5d85d35d6}
CLSIA|{faff0003-0a01-121a-a1c9-08032b23e0cc}
CLSIA|{ff3f0f03-0f01-131a-a3f9-08f02b23e0cc}
CLSIA|{fffb1d8b-88d6-4c91-bb62-378625e8c73e}
CLSIA|{ffff0018-0001-101a-a3c9-08002b2f49fb}
DIREC|%ProgramFiles%\GlobalDialer\
AUTST|sws.exe
AUTST|w32sup
CLASS|Gxbplug.plug
CLASS|Loader.LoaderObj
CLASS|OLibrary.IEPlugIn
CLASS|Suchspur.SuchspurObj
RKSOF|Gxb
UINST|GlobalDialer
FILEN|gd-ff_be.exe
FILEN|gd-ff_us.exe
FILEN|gdnca167.exe
FILEN|globaldialer.cab
FILEN|olibrary.dll
NEWPR|2512|GoIn Direct Dialer
PRCAT|8
NEWPR|645|Hacker Spider
PRCAT|8
DIREC|%windir%\coder
UINST|Exclusiver Bereich
FILEN|%userprofile%\Desktop\Exclusiver Bereich.lnk
FILEN|%userprofile%\Start Menu\Programs\Exclusiver Bereich.lnk
FILEN|hacker spider.exe
NEWPR|709|Haldex
PRCAT|8
DIREC|%programfiles%\HaldexLtd\
NEWPR|407|HighSpeed Connector
PRCAT|8
FILEN|123-sexkino.exe
FILEN|aktgirls.exe
FILEN|aktshow.exe
FILEN|amateur-hardcore-sex.exe
FILEN|analorgasmus.exe
FILEN|analxxx.exe
FILEN|babesex.exe
FILEN|begleitung-online.exe
FILEN|berlin-erotik.exe
FILEN|betnaker.exe
FILEN|bigbusen.exe
FILEN|bumsmich.exe
FILEN|bundesligagirls.exe
FILEN|busencam.exe
FILEN|busenline.exe
FILEN|busenshow.exe
FILEN|busentreff.exe
FILEN|busenweb.exe
FILEN|camcontrol.exe
FILEN|casarossa.exe
FILEN|city-girls.exe
FILEN|clickfick.exe
FILEN|computersex.exe
FILEN|cyber-angels.exe
FILEN|cybererotiva.exe
FILEN|debabes.exe
FILEN|degirls.exe
FILEN|deutsch.exe
FILEN|devotelust.exe
FILEN|disnex.exe
FILEN|donnavargas.exe
FILEN|dream-sex.exe
FILEN|e-kontakte.exe
FILEN|ecsfun.exe
FILEN|ero-world.exe
FILEN|eroclick.exe
FILEN|eroklick.exe
FILEN|erophone.exe
FILEN|eroplanet.exe
FILEN|erotic-news.exe
FILEN|eroticenter.exe
FILEN|eroticliveshow.exe
FILEN|erotik-news.exe
FILEN|euromodels2.exe
FILEN|fickclick.exe
FILEN|fickenonline.exe
FILEN|fickklick.exe
FILEN|fickline.exe
FILEN|fickschule.exe
FILEN|ficksie.exe
FILEN|fussballgirls.exe
FILEN|germany.exe
FILEN|gina-wild-sex.exe
FILEN|girls.exe
FILEN|girlsbesuch.exe
FILEN|girlshotel.exe
FILEN|girlstalk.exe
FILEN|glas-haus.exe
FILEN|hardcore-live-sex.exe
FILEN|hooters.exe
FILEN|hotbunny.exe
FILEN|hotelbesuch.exe
FILEN|hotelgirls.exe
FILEN|hotpower.exe
FILEN|hotvot.exe
FILEN|hotwied.exe
FILEN|klickfick.exe
FILEN|kontaktechat.exe
FILEN|lesbenhaus.exe
FILEN|life-girl.exe
FILEN|lifegirl.exe
FILEN|live-studio.exe
FILEN|livechatcam.exe
FILEN|livephone.exe
FILEN|livesex.exe
FILEN|livesexkanal.exe
FILEN|liveshow.exe
FILEN|lovephone.exe
FILEN|lucky-punch.exe
FILEN|macronedia.exe
FILEN|maxxcafe.exe
FILEN|meetboys.exe
FILEN|meinecam.exe
FILEN|moesenhaus.exe
FILEN|mytits.exe
FILEN|nacktshow.exe
FILEN|nudeliveshow.exe
FILEN|online-begleitung.exe
FILEN|online-escort.exe
FILEN|orgasmusbilder.exe
FILEN|orgasmusline.exe
FILEN|orgasmuslive.exe
FILEN|orgasmusparty.exe
FILEN|orgasmusvideo.exe
FILEN|osnastrip.exe
FILEN|pagesex.exe
FILEN|pam.exe
FILEN|peep-show-girls.exe
FILEN|persiankitti.exe
FILEN|persianklitty.exe
FILEN|phonegirl.exe
FILEN|phythom.exe
FILEN|playboobs.exe
FILEN|playgal.exe
FILEN|playmoesen.exe
FILEN|playmuschi.exe
FILEN|porncam.exe
FILEN|porno-porno-sex-sex.exe
FILEN|pornodelux.exe
FILEN|pornomoesen.exe
FILEN|privatbesuch.exe
FILEN|pussygeil.exe
FILEN|pussyhaus.exe
FILEN|redlightgirls.exe
FILEN|rotlichtchat.exe
FILEN|rotlichtgirls.exe
FILEN|rotlichtline.exe
FILEN|rotlichtshow.exe
FILEN|schulsex.exe
FILEN|sex-erotik-show.exe
FILEN|sex-live-chat.exe
FILEN|sex-porno-show.exe
FILEN|sex-rooms.exe
FILEN|sex-sex-porno-porno.exe
FILEN|sex-sex-sex-pussy.exe
FILEN|sex-tabulos.exe
FILEN|sexcall.exe
FILEN|sexdominanz.exe
FILEN|sexevents.exe
FILEN|sexfetish.exe
FILEN|sexillusion.exe
FILEN|sexkarussell.exe
FILEN|sexkeller.exe
FILEN|sexme.exe
FILEN|sexmich.exe
FILEN|sexpicturegallery.exe
FILEN|sexroulette.exe
FILEN|sexschule.exe
FILEN|sextacy.exe
FILEN|sexycamera.exe
FILEN|smutlamd.exe
FILEN|soos.exe
FILEN|strapsshow.exe
FILEN|strichgirls.exe
FILEN|strip-eonline.exe
FILEN|strip-girls.exe
FILEN|stripcan.exe
FILEN|striplime.exe
FILEN|stripline.exe
FILEN|strippenonline.exe
FILEN|stripschule.exe
FILEN|studiosex.exe
FILEN|suendenspiele.exe
FILEN|teenmail.exe
FILEN|telestrip.exe
FILEN|the-sweets.exe
FILEN|tittengeil.exe
FILEN|tittenline.exe
FILEN|tittenseite.exe
FILEN|tittenspiele.exe
FILEN|tittenweb.exe
FILEN|tittenwelt.exe
FILEN|travelsex24.exe
FILEN|venusgirls.exe
FILEN|venusphone.exe
FILEN|victoriasecreet.exe
FILEN|videochatcam.exe
FILEN|viona.exe
FILEN|vollbusicam.exe
FILEN|wichsen.exe
FILEN|wild-sex.exe
FILEN|xxxphone.exe
NEWPR|1238|Holystic
PRCAT|8
CLSIA|{037b3d58-d14a-4c41-bdfd-bd779b0b97ba}
CLSIA|{03c543a1-c090-418f-a1d0-fb96380d601d}
CLSIA|{0733b8f9-8b52-4693-a9fa-829e12d27f78}
CLSIA|{0873478e-e67a-4876-b0a9-9a36d3ab3602}
CLSIA|{0cb2bd5a-7a80-4ba9-b49a-02dc51144bdf}
REGKE|HKEY_CLASSES_ROOT\HOL3_VXIEWER.FULL.1
REGKE|HKEY_CLASSES_ROOT\HOL_PRELOAD.FULL.1
NEWPR|408|HotActionDating
PRCAT|8
FILEN|hotactiondating-uninstall.exe
FILEN|hotactiondating.exe
FILEN|nsi145.exe
NEWPR|2583|Hot_Pleasure
PRCAT|8
REGKE|HKEY_CURRENT_USER\Software\SiteIcons\Dialers
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pmxy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-pmxy
AUTST|LiveSexCams
CLASS|pmxy File
UINST|LiveSexCams
FILEN|%USERPROFILE%\Desktop\LiveSexCams.lnk
NEWPR|771|Ibero Dialer
PRCAT|8
CLSIA|{19e0f68f-c0ef-4241-b876-a3d646995895}
CLSIA|{1d7532ce-995b-40f2-8c17-2e01af16ffac}
CLSIA|{2c0f2aea-3a9b-46db-a7be-80ff329e415d}
CLSIA|{571c345e-7356-444b-a4e2-1b6442f96ebc}
CLSIA|{b15108aa-d8d0-480d-b535-07e18d6549a8}
CLSIA|{fb8d70e2-554a-4c75-90be-66c302367e0d}
FILEN|ppremiuminternacional.dll
NEWPR|432|IBS
PRCAT|8
FILEN|gratis-sex-crack.exe
FILEN|traumdate.exe
NEWPR|456|IEAccess
PRCAT|8
CLSIA|{0594af7e-573b-40df-8165-e47ab2eaefe8}
CLSIA|{11f1d260-129e-4eb7-b37e-57e3d97a3df1}
CLSIA|{1a9ec776-942a-4a51-8cd6-0dd9c25ed05b}
CLSIA|{1d2dca0d-b30f-40ad-9690-087105f214ec}
CLSIA|{1eb17d1c-141d-4d9d-91cb-24d99215851d}
CLSIA|{2abe804b-4d3a-41bf-a172-304627874b45}
CLSIA|{2aeeac34-fd74-4142-b891-4b05c0c03c87}
CLSID|{2f668a6d-2ec7-4e3a-a485-819e210738d6}
CLSID|{4209b4c1-1295-4908-9312-a53c036eb3cd}
CLSIA|{469c7080-8ec8-43a6-ad97-45848113743c}
CLSIA|{486e48b5-abf2-42bb-a327-2679df3fb822}
CLSIA|{50ad557e-3426-41fd-afdd-2af39bb1c387}
CLSID|{62bfaec2-82a5-4117-a98b-fea89413d924}
CLSIA|{6aa93df6-6757-4338-9087-f7601de18402}
CLSIA|{71cbdcd9-0830-4470-a890-35d364da352c}
CLSID|{7699aef9-f83a-44fa-b374-aa02cedf247d}
CLSIA|{77ef6dbf-3929-4081-af2e-178d387e211c}
CLSIA|{79733e69-6e1c-4682-bdf5-710d217a4125}
CLSID|{81c2f7f3-f930-455e-9aa5-0876d387c787}
CLSID|{83f0d6aa-cd15-46b5-aa4e-bdb506b4ae53}
CLSIA|{8b936702-c234-40d0-b69c-a2f669a33978}
CLSID|{901166a5-f137-4b27-bc4c-ca611debdced}
CLSIA|{946b0485-8f8c-4c35-a6e7-d2115e3b0b4f}
CLSIA|{94f5dcb7-816c-4b94-a2c1-856c6e323c5b}
CLSIA|{99ff4323-e68c-46dc-8f48-1f79a7005336}
CLSIA|{9c020689-fa7d-4d8d-be7e-dc263791cb29}
CLSIA|{9ef4e3e4-2f1e-472e-9ff2-2670ea5c42d9}
CLSIA|{a02780c3-7f77-4e28-855b-28890f3cf37a}
CLSIA|{afcf364f-f730-4b1e-b2d5-80f9172fbc44}
CLSIA|{b843da96-2b2d-447e-90ab-b92929aa11af}
CLSIA|{bd3653e4-884b-43c4-970b-670802501b7f}
CLSIA|{be5a7132-329f-4319-b781-2a83bfe51534}
CLSIA|{c20eb175-0dd0-4979-a994-1f0dba69f627}
CLSIA|{c9269872-e3d6-4811-8e5e-835ca8cbd0b3}
CLSIA|{caaf9105-a683-4ed1-89cc-18f6d194dd84}
CLSIA|{cdd8bade-b4c8-4e97-84b4-1dc9abad3ef3}
CLSIA|{cefb7b49-9652-464f-8afd-a577c0500f39}
CLSIA|{cf5f84eb-d3fc-4f98-be3b-f5b56b962ced}
CLSIA|{d8b94e9a-a34b-4253-bf48-c7cb7f2cfdb0}
CLSIA|{eeeca057-ad0f-44a7-8be5-8634cedbdbd1}
CLSIA|{f513e3da-5579-4981-8abc-99e411893c3d}
CLSIA|{f72bc3f0-6c20-4793-9dda-258589d8a907}
CLASS|egdhtml.egdialhtml
CLASS|eghtmldialer.htmldialer
CLASS|IEAccess2.IEDial
RKSOF|DIALPASS
RKSOF|egdhtml
RKSOF|egroup
FILEN|egdhtml_1015.dll
FILEN|egdhtml_1017.dll
FILEN|egdhtml_1020.dll
FILEN|egdhtml_1021.dll
FILEN|egdhtml_1023.dll
FILEN|egdhtml_1024.dll
FILEN|egdhtml_1025.dll
FILEN|egdhtml_1026.dll
FILEN|egdhtml_1027.dll
FILEN|egdhtml_1029.dll
FILEN|eghtmldialer.dll
FILEN|ieaccess2.cab
FILEN|ieaccess2.dll
FILEN|iedisco.exe
FILEN|nethv32_en_xp.cab
NEWPR|817|Instant-Access
PRCAT|8
CLSIA|{01be5bd7-b2dd-48b3-a759-59265a91e787}
CLSIA|{04ccff26-7d52-4e42-bf6a-f8ece0896eb7}
CLSIA|{04f414e9-e352-4bc3-963d-7bfe5a5f31a9}
CLSIA|{07c9cfc7-de33-4a0c-9ffb-cdfba843b157}
CLSIA|{0d1011b3-89c8-4f8e-8693-bb970e2e81e0}
CLSIA|{0da910bc-6919-489e-b584-d9a4aac7b8de}
CLSIA|{15d0e439-4e58-45e1-a9c1-0b1b16749a3c}
CLSIA|{1604df98-d1a5-44fe-844a-98d6fd0518d0}
CLSIA|{17bfc8da-b4d6-4db9-aa40-1cd32eda9845}
CLSIA|{1cd49dc9-fd88-41fa-b892-47e037267d45}
CLSIA|{201d3da8-b495-4a3b-bee8-6d8ddccc5762}
CLSIA|{26d73573-f1b3-48c9-a989-e6
ce071957a1}
CLSIA|{31ddc1fd-cea3-4837-a6dc-87e67015adc9}
CLSIA|{3446598e-00e4-4b5e-99a6-87ecca8324a2}
CLSIA|{3616f4b5-f6ad-4e67-966a-c218673648a0}
CLSIA|{3dad912e-d2b9-4323-b7c9-7f2c5cc0c57b}
CLSIA|{54579c3d-a58d-4623-b5b5-465552bda45b}
CLSIA|{624321f1-0581-49d8-99bd-2e952c2df31b}
CLSIA|{7504f0d5-644a-4103-9d02-95488b6cb9a1}
CLSIA|{78f584df-bbf5-4296-839c-31de60914dbc}
CLSIA|{8d8baf56-b581-4b90-a549-c4ac6b03f1bb}
CLSIA|{95460abd-946a-46ff-9f56-268718323eee}
CLSIA|{a1c392a2-b274-46db-89be-1fbd476b9c93}
CLSIA|{b2b0aedf-7cdf-4792-bb67-7654ad1e1b13}
CLSIA|{ba749bc1-143e-430d-b1da-1d2af67a3658}
CLSIA|{bfc9677b-8006-4336-9d49-2c797aefcb9e}
CLSIA|{c2481ed1-9896-4d49-ae90-69858dfde446}
CLSIA|{c6760a07-a574-4705-b113-7856315922c3}
CLSIA|{e114cd5b-17ce-4807-890e-7b1edf9f2e5e}
CLSIA|{e19ab99f-aec4-4b40-a5ca-f69d22522d77}
CLSIA|{e24e8472-89b7-479f-8ad8-bbd7206a6a02}
CLSIA|{e3943a24-2f83-4505-9ae5-f705e81b50cb}
CLSIA|{e7ae1661-ebeb-492b-ae0d-860df24174c6}
CLSIA|{ef4dcd99-d26b-44a4-ba77-cfdcc97e7291}
CLSIA|{efb23983-5803-4914-ada3-c0ea2cfbdc37}
CLSIA|{fa605711-8e72-46b2-ae49-bed11b2e729d}
CLSIA|{fa83e942-b796-46de-9155-1632ecc5473b}
DIREC|%ProgramFiles%\Instant Access\
AUTST|dubiloa
AUTST|Instant Access
AUTST|MovieNetworks Instant Access
FILEN|%ALLUSERSPROFILE%\Desktop\NoCreditCard.lnk
FILEN|%userprofile%\Desktop\Instant Access.lnk
FILEN|%USERPROFILE%\Start Menu\Instant Access.lnk
FILEN|%USERPROFILE%\Start Menu\NoCreditCard.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Instant Access.lnk
FILEN|egdaccess_1059.cab
FILEN|egdaccess_1059.dll
FILEN|egdaccess_1063.dll
FILEN|egdaccess_1063_xp.cab
FILEN|egdaccess_1064.dll
FILEN|egdaccess_1064_xp.cab
FILEN|egdaccess_1065.dll
FILEN|egdaccess_1065_aspiv4_xp.cab
FILEN|egdaccess_1065_xp.cab
FILEN|egdaccess_1066.dll
FILEN|egdaccess_1066_aspiv4.cab
FILEN|egdaccess_1066_xp.cab
FILEN|egdaccess_1067_aspiv4_xp.cab
FILEN|egdaccess_1068_aspiv4.cab
FILEN|egdaccess_1070_aspiv4_xp.cab
FILEN|egdaccess_1071.dll
FILEN|egdaccess_1071_aspiv4_xp.cab
FILEN|egdaccess_1071_xp.cab
FILEN|egdaccess_1072.dll
FILEN|egdaccess_1072_aspiv4_xp.cab
FILEN|egdaccess_1072_xp.cab
FILEN|egdaccess_1073.dll
FILEN|egdaccess_1073_aspiv4_xp.cab
FILEN|egdaccess_1073_xp.cab
FILEN|egdaccess_1074.dll
FILEN|egdaccess_1074_xp.cab
FILEN|egdaccess_aspiv4_1065.dll
FILEN|egdaccess_aspiv4_1066.dll
FILEN|egdaccess_aspiv4_1067.dll
FILEN|egdaccess_aspiv4_1068.dll
FILEN|egdaccess_aspiv4_1070.dll
FILEN|egdaccess_aspiv4_1071.dll
FILEN|egdaccess_aspiv4_1072.dll
FILEN|egdaccess_aspiv4_1073.dll
NEWPR|938|Interfun
PRCAT|8
CLSIA|{15c3c7a4-9676-11d3-9799-0060087190b9}
NEWPR|470|IpBill.Dialer
PRCAT|8
CLSID|{19e91d82-7ad7-419f-866a-58c122db1459}
CLSID|{266f948a-3dee-4270-8f55-e79accd569fa}
CLSID|{90a52f00-64ac-4dc6-9d7d-4516670275d0}
CLSIA|{9e1089bc-1ae8-4685-8d77-6721e5c318a8}
CLSIA|{ad7fafb0-16d6-40c3-af27-585d6e6453fd}
CLSIA|{c68ae9c0-0909-4ddc-b661-c1afb9f5ae50}
CLSID|{f5f779a9-24e5-4bcd-9ae5-6313d4b5ac24}
REGKE|HKEY_CLASSES_ROOT\comload.loader2 loader2 Class
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/comload.dll
CLASS|Comload.loader
CLASS|comload.loader2
CLASS|dctl
RKSOF|coulomb
FILEN|%WinDir%\Downloaded Program Files\comload.dll
FILEN|comload.dll
NEWPR|1229|MaConnect
PRCAT|8
CLSIA|{02c20140-76f8-4763-83d5-b660107b7a90}
CLASS|MaConnect.Loader
NEWPR|2754|MadameSalope
PRCAT|8
FILEN|%USERPROFILE%\Desktop\MadameSalope.lnk
FILEN|%USERPROFILE%\Desktop\Uninstall MadameSalope.lnk
NEWPR|2490|MarcadorCOM
PRCAT|8
CLSIA|{03fbb191-fb50-4154-91d7-587d5e3c3c9a}
CLSID|{e21f253b-db1f-451b-b1f2-8b5aa5a760fd}
CLSID|{e5b6dc84-fa86-4d2e-9fc7-4582b4770f3b}
CLASS|MarcadorCOM.Marcador
NEWPR|812|Masta Cash Dialer
PRCAT|8
CLSID|{92abacfe-ef6e-42c7-a824-d50a914b5b70}
CLASS|Loader.LoaderX
NEWPR|523|MasterDialer
PRCAT|8
CLSIA|{12e5e9d9-4366-45d9-ba41-d0bcd55ad8cf}
CLSIA|{16a7470e-229c-45f9-ae05-a87034fd14cf}
CLSIA|{2f0d1da3-f3e4-4c67-bb5c-5afd70c1a4a5}
CLSIA|{5c24626a-cc0d-49d6-8454-aaa5b97d4410}
CLSIA|{788a7678-38d7-4eec-9d20-67a86d21a7fd}
CLSIA|{b663a561-7424-4958-af76-853e80b4e1c6}
CLSIA|{d62b5127-8d03-4175-ba71-e0041595da4b}
CLSIA|{e9c87343-0e63-4aca-9b76-b155333ee67a}
NEWPR|489|MoneyTree
PRCAT|8
CLSIA|{11b6f65d-7b8d-43cb-9aae-17234a1db33a}
CLSIA|{405fd721-04ef-4ef2-ab96-fb31d32d4643}
CLSIA|{563e5df0-2c1c-4513-bbf5-d380536bb8fc}
CLSIA|{8f4e5661-f99e-4b3e-8d85-0ea71c0748e4}
CLSIA|{96b01a48-1317-4a87-91f7-10116f755705}
CLSIA|{9f2c17ac-9aa4-4c3a-82c7-ea7bcf00f03d}
CLSIA|{a0f0d762-d1de-43af-b70e-d87864743eb3}
CLSIA|{bf279130-3f58-4e26-8043-cd5688a4d4c9}
CLSIA|{c3fda8ce-9414-4e33-ac6b-4922922259a5}
CLSIA|{c89bb48c-15d9-4f4f-803e-95d90f62be62}
CLSIA|{ca7ccb52-6922-47e5-b784-3a3f82c51863}
CLSIA|{cc87b8b6-5947-46fa-9734-68196fcf9632}
CLSIA|{da9a0b1e-9b7b-11d3-b8a4-00c04f79641c}
CLSIA|{e8edb60c-951e-4130-93dc-faf1ad25f8e7}
CLSIA|{f332d106-2ef3-45c4-baf2-0f739d76b26a}
CLSIA|{f7f808f0-6f7d-442c-93e3-4a4827c2e4c8}
CLSIA|{fc87a650-207d-4392-a6a1-82adbc56fa64}
REGKE|HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/unidist.ocx
AUTST|dyfuca
AUTST|wjarafyb
CLASS|multidist.multidistctrl
CLASS|UNIDIST.UniDistCtrl
RKSOF|FCI
UINST|Hardcore
FILEN|muldist.ocx
FILEN|nem210.dll
FILEN|nem212.dll
FILEN|nem213.dll
FILEN|nem214.dll
FILEN|nem215.dll
FILEN|nem216.dll
FILEN|nem217.dll
FILEN|nem218.dll
FILEN|nsupd9x.cab
FILEN|nsupdate.dll
FILEN|unidist.ocx
FILEN|view_sex_now.exe
FILEN|wsem210.dll
FILEN|wsem213.dll
FILEN|wsem214.dll
FILEN|wsem215.dll
FILEN|wsem216.dll
FILEN|wsem218.dll
FILEN|wsem301.dll
FILEN|wsem302.dll
NEWPR|1817|Montil
PRCAT|8
CLSIA|{a41c6220-6f42-4646-b119-fbe6f4d38e3c}
CLSIA|{d1b80ebf-1a26-4fec-b0b9-dcb934c6507e}
CLASS|AccesMembre.Loader
NEWPR|1414|Movieplace
PRCAT|8
DIREC|%programfiles%\MoviePlace
AUTST|MoviePlace
NEWPR|1794|MSConnect Dialer
PRCAT|8
CLSIA|{8b22270a-71d9-4ab9-b11a-2ea1e5292f42}
NEWPR|409|Net900
PRCAT|8
FILEN|net900.exe
NEWPR|2515|NetVenda
PRCAT|8
NEWPR|2261|NetVision
PRCAT|8
CLSIA|{db893839-10f0-4af9-92fa-b23528f530af}
DIREC|%USERPROFILE%\Start Menu\Programs\FASTTRACK\
AUTST|FASTTRACKNETVISION
RKSOF|FASTTRACK
RKSOF|NETVISION
FILEN|%USERPROFILE%\Desktop\Adulti.lnk
FILEN|%USERPROFILE%\Desktop\NETVISION.lnk
FILEN|%USERPROFILE%\Desktop\Sfondi.lnk
NEWPR|2246|New Dial
PRCAT|8
NEWPR|1297|NoCreditCard Sex Dialer
PRCAT|8
NEWPR|2457|Nunci
PRCAT|8
CLSID|{da002853-42d9-4a47-a236-896d32bb7ec7}
CLSID|{ffb51760-344e-4ffb-bfff-4b18c7ac1d63}
CLSIA|{ffff0003-0001-101a-a3c9-08002b2f49fb}
DIREC|%windir%\system32\Foox
DIREC|%windir%\system32\Goox
DIREC|%windir%\system32\Winteg
DIREC|%windir%\system32\Wintx
DIREC|%WINDIR%\system32\Winx\
AUTST|Connector
AUTST|Connectors
AUTST|Winsystem
AUTST|Winsystems
RKSOF|Freeware\{DA002853-42D9-4A47-A236-896D32BB7EC7}
RKSOF|Freeware\{FFB51760-344E-4FFB-BFFF-4B18C7AC1D63}
UINST|{204131AB-C727-4CF2-8230-F47D6B1FFF70}
UINST|{30083491-2978-45D6-8BD4-DBBEB4A1AB59}
UINST|{54F7FD6E-E782-4F9F-8FF0-677090048729}
UINST|{766AF492-15F9-4C69-B73A-3D204B4C331B}
UINST|{8700A5F0-4867-41C8-AD94-7C15C0E03F8D}
FILEN|%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Night Club - Foto Annunci Video - VM18.lnk
FILEN|%USERPROFILE%\Desktop\FOTO E VIDEO DI RAGAZZE BELLISSIME.lnk
FILEN|%USERPROFILE%\Desktop\FOTO VIDEO CAM e tanto altro.?lnk
FILEN|%USERPROFILE%\Desktop\LOGHI SUONERIE E TANTO ALTRO .?lnk
FILEN|%USERPROFILE%\Desktop\Night Club - Foto Annunci Video - VM18.lnk
FILEN|%USERPROFILE%\Desktop\VIDEOCHAT GIRLS.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Night Club - Foto Annunci Video - VM18.lnk
NEWPR|1291|One2Bill
PRCAT|8
CLSIA|{00000000-6666-0704-0b53-2c8830e9faec}
CLSIA|{00000000-7777-0704-0b53-2c8830e9faec}
NEWPR|524|Online-Dialer
PRCAT|8
CLSID|{8512b008-b0aa-451f-a744-a289fd8ffde6}
CLSID|{abc7630f-71ce-4a96-9aa6-0469457b9ba3}
CLASS|Ole32ws.Moniker32
FILEN|maconnect.cab
FILEN|maconnect.dll
FILEN|od-dflt0001.exe
FILEN|od-stnd191.exe
FILEN|ole32ws.dll
NEWPR|1974|Orgasm dialer
PRCAT|8
FILEN|%systemroot%\Orgasm.exe
FILEN|%userprofile%\Desktop\Orgasm.lnk
FILEN|%userprofile%\Start Menu\Orgasm.lnk
FILEN|30500105.exe
NEWPR|789|ParisVoyeur
PRCAT|8
CLSIA|{869518c3-fba5-4d75-8a14-7047437e9498}
CLSIA|{90d610e8-f6d0-4ad4-93ce-178a46f8c412}
CLSIA|{b4e0f9cb-bc06-4a33-bbb3-f75f16b6ff5e}
DIREC|%ProgramFiles%\Montorgueil\
DIREC|%WINDIR%\Temp\MT\
RKSOF|Montorgueil
FILEN|parisvoyeur.exe
NEWPR|2592|PersonalMoneyTree
PRCAT|8
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\PMT
DIREC|%ProgramFiles%\Personal Money Tree\
DIREC|%userprofile%\Start Menu\Programs\Personal Money Tree\
UINST|Personal Money Tree
NEWPR|579|PluginAccess
PRCAT|8
CLSIA|{a1dc3241-b122-195f-b21a-000000000000}
CLSIA|{e21ae2d7-972c-4d23-bee7-a902122841e6}
FILEN|browser_plugin.cab
FILEN|browser_plugin.exe
NEWPR|799|Porn385
PRCAT|8
NEWPR|1133|Porndialer.a
PRCAT|8
CLSID|{251347ac-229a-4df4-838c-23966e119ce3}
CLSIA|{5f426a93-0821-47d2-a126-5a48a874b289}
CLSID|{9007d402-bf5c-410c-b958-9994c88d943b}
CLASS|PDialerWeb.DialerWeb
NEWPR|501|Proclaim Dialers
PRCAT|8
CLSIA|{d53b810f-6219-11d4-95b6-00
40950375e7}
FILEN|hotsurprise_be.exe
FILEN|ukvideo2.exe
NEWPR|2451|Progetto
PRCAT|8
CLSIA|{0d62a517-e7c6-4e1f-a577-07d4ac549a48}
CLSID|{391f0ac2-2cfc-4d56-a0e5-c7beb14f26e6}
CLSID|{62753dcb-b56b-46c1-831c-93387ec8135a}
CLSIA|{a1426ac5-8ce5-4a00-b71e-011d35709ac6}
CLSIA|{b7e76c25-791f-432e-bdb7-748d01a93fc2}
CLASS|Progetto1.int_ver32
CLASS|Progetto1.int_ver34
CLASS|VacPro.int_ver30
NEWPR|3509|Qdialer
PRCAT|8
NEWPR|2274|QucktIme.dialer
PRCAT|8
AUTST|bodr.exe
NEWPR|2471|RASDial-E
PRCAT|8
CLSIA|{fbff6f10-abcd-9544-832f-a1f75a0501ae}
NEWPR|1789|SCData Dialer
PRCAT|8
CLSIA|{3ecf916f-a5de-4dd4-a142-b35a29dc2edb}
CLSIA|{6ed16eff-3b18-11d6-9139-00e02964e8e3}
NEWPR|2804|Scom Dialer
PRCAT|8
DIREC|%ProgramFiles%\scom
AUTST|Gay_Sexy
RKSOF|SCom
UINST|Gay_Sexy
FILEN|%USERPROFILE%\Desktop\Gay_Sexy.lnk
FILEN|%USERPROFILE%\Start Menu\Gay_Sexy.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Gay_Sexy.lnk
NEWPR|855|SexFiles
PRCAT|8
NEWPR|2432|Sexnow
PRCAT|8
AUTST|Sexnow
FILEN|%USERProfile%\Desktop\Sexnow.lnk
FILEN|%USERPROFILE%\Start Menu\Sexnow.lnk
NEWPR|1796|SexoBFAX Dialer
PRCAT|8
CLSID|{8f575708-0000-0000-0000-000000000000}
NEWPR|1795|SexoDial
PRCAT|8
CLSIA|{8e65b894-c2e9-11d5-bcd3-00e018987501}
CLSIA|{8e65b894-c2e9-11d5-bcd3-00e018987519}
NEWPR|2419|SexyBills
PRCAT|8
NEWPR|1785|SinCity
PRCAT|8
CLSIA|{4e15d681-1d20-11d4-8b72-000021da1956}
NEWPR|2552|SkyMaster
PRCAT|8
IEZON|archiviosex.net
NEWPR|1809|SmsDialer
PRCAT|8
CLSIA|{bd11a280-2e73-11cf-b6cf-00aa00a74dae}
FILEN|%USERPROFILE%\Desktop\Kontakt Annonser.lnk
FILEN|%USERPROFILE%\Desktop\Sexleksaker.lnk
FILEN|%USERPROFILE%\Desktop\SMS KUL.lnk
NEWPR|1311|Softtec Dialer
PRCAT|8
CLSIA|{5df6fb84-749d-4aae-ae37-708de09b0588}
NEWPR|2610|SPlanet
PRCAT|8
CLSIA|{00000000-0023-0000-5400-320020040070}
NEWPR|414|StarDialer
PRCAT|8
CLSID|{c34827ea-8777-4917-927c-8f8fae1a3815}
CLSID|{d037f883-92c3-4f89-a302-c01127cf3c72}
CLSIA|{e0b795b4-fd95-4abd-a375-27962efce8cf}
CLSID|{f0bc061f-daf9-4533-8011-53bcb4c10307}
CLSID|{f1cc694e-9e9d-4913-ac41-2970aeef2bf0}
CLASS|InstallationsAssistent
RKSOF|MainPean Highspeed
FILEN|britney spears nackt.exe
FILEN|hzs-10030.exe
FILEN|starinstall.ocx
NEWPR|455|StripPlayer
PRCAT|8
CLSID|{357aa41a-b7a8-4632-a27d-5b980b25cf43}
CLSID|{bc23f736-c5be-47fb-b459-1757933e5df3}
CLSIA|{e3f7205f-2ae0-4bf0-816b-2d24a5f20ec7}
FILEN|activestripsetup.cab
FILEN|activestripsetup.dll
FILEN|stripsetup.exe
NEWPR|1949|Switchdialer
PRCAT|8
CLSIA|{5cbf8c22-e9a6-11d7-90fe-000ae4012db4}
DIREC|%ProgramFiles%\Make125\
AUTST|sVideo2
RKSOF|Make125
RKSOF|SwitchDialer
UINST|Switch
NEWPR|644|SystemVXD Dialer
PRCAT|8
FILEN|systemvxd.exe
NEWPR|1279|Sysupd
PRCAT|8
AUTST|JavaUpdate0.07
AUTST|SysUpd
NEWPR|2574|Tele Team Work Dialer
PRCAT|8
NEWPR|2482|Telemedia
PRCAT|8
CLSID|{855fb119-4791-423b-bc32-ba7e9f037bb1}
CLSID|{c1c0b1a9-fd3a-4f0b-b825-397d26f01e36}
REGKE|HKEY_CLASSES_ROOT\DIALERX.DialerXCtrl.1
NEWPR|580|TIBS
PRCAT|8
CLSIA|{0191abf4-9421-435e-9ffd-cd827a2a82d8}
CLSID|{0f9561d0-03b2-44a3-89a6-e95e417cba25}
CLSIA|{10a1b95d-5e35-4935-8bc3-d43e81e8105e}
CLSIA|{1e89f686-b78d-4c85-9efc-3474516e3fe2}
CLSID|{38d4d5d0-423e-4220-b6f9-30918c2ae4a4}
CLSID|{5ff31463-6856-4604-bee9-d84c92f60ba4}
CLSIA|{a51dedcd-20f7-11d4-98a5-00c0ca130748}
CLSIA|{b73bc7c7-858b-49fa-bbdb-74dd77d1d9f3}
CLSIA|{c1c2ac28-5e4b-4228-b7a0-05e986ffce14}
CLSID|{d88da98d-48ba-4116-96ab-77c38eae487f}
DIREC|%PROGRAMFILES%\WEBSITEVIEWER\
CLASS|atlbrcon.atlbrcon
CLASS|LoaderCon.LoaderCon
CLASS|TIBSLoaderAXDLL.TIBSLoader
RKSOF|dialer\Nude Celebrities ! \
RKSOF|TBS
RKSOF|WebSiteViewer
FILEN|%USERProfile%\Desktop\sex.lnk
FILEN|%USERProfile%\Start Menu\sex.lnk
FILEN|clbmn2.exe
FILEN|tibsloader.exe
FILEN|tl4000.dll
NEWPR|932|ToneLoc 1.1
PRCAT|8
NEWPR|2781|Trojan.Win32.Dialer.ow
PRCAT|8
NEWPR|410|TSCash
PRCAT|8
CLSIA|{13258718-b804-4092-8496-55f80aedbf1f}
CLSIA|{52290b25-d07a-43b5-84d8-493116d50fa0}
CLSIA|{de726bc4-5f2f-4984-b28b-3d6d76724f64}
FILEN|adult.exe
FILEN|cammaus.exe
FILEN|deutsche-peepshow.exe
FILEN|erotik-hotel.exe
FILEN|funland.exe
FILEN|lustmaus.exe
FILEN|megabusen.exe
FILEN|nutte.exe
FILEN|sabine.exe
FILEN|sabine2.exe
FILEN|sexstop.exe
FILEN|spanner.exe
FILEN|stchat.exe
FILEN|telefun.exe
FILEN|tscash.exe
FILEN|tscash3nos.cab
FILEN|ueber40de.exe
FILEN|xxxlivesex.exe
NEWPR|2315|Ulubione
PRCAT|8
AUTST|Ulubione
NEWPR|403|Unknown Dialers
PRCAT|8
CLSIA|{00000012-890e-4aac-afd9-kjt4964a34df}
CLSIA|{12345678-baba-caca-dada-babacacadada}
CLSIA|{1261803f-da51-4dfd-b1b6-8e26fe3d8399}
CLSIA|{13f90341-ad79-4a9f-9b57-0234675670d6}
CLSIA|{15589fa1-c456-11ce-bf01-00aa0055595a}
CLSIA|{1d4bd875-c3d8-4476-a066-3b16d2cb1ea5}
CLSIA|{1e1b2879-88ff-11d2-8d96-d7acac97972f}
CLSIA|{214868a8-f71b-473e-8ecf-6ee1de6b91d8}
CLSID|{21de6877-97c0-4fc7-9c16-666b996db4a2}
CLSIA|{28383874-c021-41be-85bd-2bba0ed4cd20}
CLSIA|{2e77e33f-671e-4334-abaa-0c2e2be654f1}
CLSIA|{38572dee-c460-481f-aa55-6289e5079ed9}
CLSIA|{3f5a62e2-51f2-11d3-a075-cc7364cae42a}
CLSIA|{41770406-8d8b-4e77-81bd-459f191f4347}
CLSIA|{459729ac-727d-4d97-b18a-72ee224efec0}
CLSIA|{459c8f4c-7b71-48e2-af72-2bb79053a5f4}
CLSIA|{50a28604-52f2-11d6-8f0f-5254ab11d5c2}
CLSIA|{75d1f3b2-2a21-11d7-97b9-0010dc2a6243}
CLSIA|{8403cb53-12b3-4537-9dec-4f12f70a883d}
CLSIA|{841a9192-5690-11d4-a258-0040954a01be}
CLSIA|{8699d723-6dc6-47d3-b55c-489ba006b917}
CLSIA|{8702d9e1-890b-4bf2-a233-fa44e582b2de}
CLSIA|{8886a618-b60a-4863-bd8b-42a24b14fc90}
CLSIA|{90803b38-6937-474c-8f80-ca1e2e8ea4ca}
CLSIA|{978a4db6-d22a-4d55-b350-dab71097bf69}
CLSIA|{a5e3b21e-ccbb-450e-9d0c-eef06076b856}
CLSIA|{b09b1d8b-88d6-4c91-bb62-378625e8c73e}
CLSIA|{b4a96063-9392-472b-8ea7-effedf873ace}
CLSIA|{b67e0278-cd82-4cca-ad9d-c1fbf538774a}
CLSIA|{bec21260-d115-4b49-99cb-f304032ee5ae}
CLSID|{c7abf7ae-67a7-495c-88e1-3d1b295e25f7}
CLSIA|{d6bd21b2-32fd-4a56-ae46-fba65eabb3a7}
CLSIA|{d9545080-34ff-4538-9419-cbe403f4885b}
CLSIA|{e2892c3d-8273-44a0-9ae7-a8d25dab81b0}
CLSIA|{efb22865-f3bc-4309-adfa-c8e078a7f762}
CLSIA|{f08555b1-9cc3-11d2-aa8e-000000000000}
CLSIA|{f1bc7ea3-a097-4c4e-9858-ab0da0f516ec}
CLSIA|{f32c4ef7-329b-4ffd-a71d-88ab39dc0849}
CLSIA|{fcaddc14-bd46-408a-9842-111111111111}
CLSIA|{fcaddc14-bd46-408a-9842-cdb57890086b}
DIREC|%userprofile%\Application Data\WinDS
DIREC|%userprofile%\Application Data\WinMS
UINST|ANIME AG
UINST|Banditos
UINST|Basteln
UINST|Download-Central
UINST|Filesharing
UINST|Firstrouting
UINST|Geburtstags- und Hochzeitsportal
UINST|Gedichte
UINST|Grusskarten Experte
UINST|Hardcore Area
UINST|Hausaufgaben
UINST|Haustiere
UINST|Jokeserver
UINST|Kazaa
UINST|Krankheiten
UINST|Krimi
UINST|Landkarte
UINST|Maerchen.ag
UINST|Malvorlagen
UINST|MobileWorld
UINST|Modeberater
UINST|Mucke.tv
UINST|Musiclab
UINST|NGFGedichte
UINST|P2P
UINST|P2P - Das Filesharingportal
UINST|Pflanzen
UINST|Piratos
UINST|Priggle
UINST|Radiofox
UINST|Routenplaner
UINST|Scoubidou
UINST|Selbst Befriedigen
UINST|Sendman
UINST|SPIELESERVER
UINST|Sportlabs
UINST|Starhacker
UINST|Suchmaschinenwelt
UINST|Tanga.AG
UINST|Tattoo
UINST|Tierheime
UINST|TOP-HUMOR
UINST|Translator
UINST|Tuxos.de
UINST|Vitalinet.de
UINST|Vorlagen
UINST|Vornamen
FILEN|%userprofile%\Desktop\ANIME AG.lnk
FILEN|%userprofile%\Desktop\Banditos.lnk
FILEN|%userprofile%\Desktop\Basteln.lnk
FILEN|%userprofile%\Desktop\Download-Central.lnk
FILEN|%userprofile%\Desktop\Filesharing.lnk
FILEN|%userprofile%\Desktop\Firstrouting.lnk
FILEN|%userprofile%\Desktop\Gamer.AG.lnk
FILEN|%userprofile%\Desktop\Geburtstags- und Hochzeitsportal.lnk
FILEN|%userprofile%\Desktop\Gedichte.lnk
FILEN|%userprofile%\Desktop\Grusskarten Experte.lnk
FILEN|%userprofile%\Desktop\Hardcore Area.lnk
FILEN|%userprofile%\Desktop\Haustiere.lnk
FILEN|%userprofile%\Desktop\Jokeserver.lnk
FILEN|%userprofile%\Desktop\Krankheiten.lnk
FILEN|%userprofile%\Desktop\Krimi.lnk
FILEN|%userprofile%\Desktop\Landkarte.lnk
FILEN|%userprofile%\Desktop\Maerchen.ag.lnk
FILEN|%userprofile%\Desktop\Malvorlagen.lnk
FILEN|%userprofile%\Desktop\MobileWorld.lnk
FILEN|%userprofile%\Desktop\Modeberater.lnk
FILEN|%userprofile%\Desktop\Mucke.tv.lnk
FILEN|%userprofile%\Desktop\Musiclab.lnk
FILEN|%userprofile%\Desktop\NGFGedichte.lnk
FILEN|%userprofile%\Desktop\P2P - Das Filesharingportal.lnk
FILEN|%userprofile%\Desktop\P2P-Filesharing.lnk
FILEN|%userprofile%\Desktop\P2P.lnk
FILEN|%userprofile%\Desktop\Pflanzen.lnk
FILEN|%userprofile%\Desktop\Piratos.lnk
FILEN|%userprofile%\Desktop\Priggle.lnk
FILEN|%userprofile%\Desktop\Radiofox.lnk
FILEN|%userprofile%\Desktop\Routenplaner.lnk
FILEN|%userprofile%\Desktop\Scoubidou.lnk
FILEN|%userprofile%\Desktop\Selbst Befriedigen.lnk
FILEN|%userprofile%\Desktop\Sendman.lnk
FILEN|%userprofile%\Desktop\SPIELESERVER.lnk
FILEN|%userprofile%\Desktop\Sportlabs.lnk
FILEN|%userprofile%\Desktop\Starhacker.lnk
FILEN|%userprofile%\Desktop\Suchmaschinenwelt.lnk
FILEN|%userprofile%\Desktop\Tanga.AG.lnk
FILEN|%userprofile%\Desktop\Tattoo.lnk
FILEN|%userprofile%\Desktop\Tierheime.lnk
FILEN|%userprofile%\Desktop\TOP-HUMOR.lnk
FILEN|%userprofile%\Desktop\Translator.lnk
FILEN|%userprofile%\Desktop\Tuxos.de.lnk
FILEN|%userprofile%\Desktop\Vitalin
et.de.lnk
FILEN|%userprofile%\Desktop\Vorlagen.lnk
FILEN|%userprofile%\Desktop\Vornamen.lnk
FILEN|%userprofile%\Start Menu\Programs\ANIME AG.lnk
FILEN|%userprofile%\Start Menu\Programs\Banditos.lnk
FILEN|%userprofile%\Start Menu\Programs\Basteln.lnk
FILEN|%userprofile%\Start Menu\Programs\Download-Central.lnk
FILEN|%userprofile%\Start Menu\Programs\Filesharing.lnk
FILEN|%userprofile%\Start Menu\Programs\Firstrouting.lnk
FILEN|%userprofile%\Start Menu\Programs\Gamer.AG.lnk
FILEN|%userprofile%\Start Menu\Programs\Geburtstags- und Hochzeitsportal.lnk
FILEN|%userprofile%\Start Menu\Programs\Gedichte.lnk
FILEN|%userprofile%\Start Menu\Programs\Grusskarten Experte.lnk
FILEN|%userprofile%\Start Menu\Programs\Hardcore Area.lnk
FILEN|%userprofile%\Start Menu\Programs\Hausaufgaben.lnk
FILEN|%userprofile%\Start Menu\Programs\Haustiere.lnk
FILEN|%userprofile%\Start Menu\Programs\Jokeserver.lnk
FILEN|%userprofile%\Start Menu\Programs\Kazaa.lnk
FILEN|%userprofile%\Start Menu\Programs\Krankheiten.lnk
FILEN|%userprofile%\Start Menu\Programs\Krimi.lnk
FILEN|%userprofile%\Start Menu\Programs\Landkarte.lnk
FILEN|%userprofile%\Start Menu\Programs\Maerchen.ag.lnk
FILEN|%userprofile%\Start Menu\Programs\Malvorlagen.lnk
FILEN|%userprofile%\Start Menu\Programs\MobileWorld.lnk
FILEN|%userprofile%\Start Menu\Programs\Modeberater.lnk
FILEN|%userprofile%\Start Menu\Programs\Mucke.tv.lnk
FILEN|%userprofile%\Start Menu\Programs\Musiclab.lnk
FILEN|%userprofile%\Start Menu\Programs\NGFGedichte.lnk
FILEN|%userprofile%\Start Menu\Programs\P2P - Das Filesharingportal.lnk
FILEN|%userprofile%\Start Menu\Programs\P2P-Filesharing.lnk
FILEN|%userprofile%\Start Menu\Programs\P2P.lnk
FILEN|%userprofile%\Start Menu\Programs\Pflanzen.lnk
FILEN|%userprofile%\Start Menu\Programs\Piratos.lnk
FILEN|%userprofile%\Start Menu\Programs\Priggle.lnk
FILEN|%userprofile%\Start Menu\Programs\Radiofox.lnk
FILEN|%userprofile%\Start Menu\Programs\Routenplaner.lnk
FILEN|%userprofile%\Start Menu\Programs\Scoubidou.lnk
FILEN|%userprofile%\Start Menu\Programs\Selbst Befriedigen.lnk
FILEN|%userprofile%\Start Menu\Programs\Sendman.lnk
FILEN|%userprofile%\Start Menu\Programs\SPIELESERVER.lnk
FILEN|%userprofile%\Start Menu\Programs\Sportlabs.lnk
FILEN|%userprofile%\Start Menu\Programs\Starhacker.lnk
FILEN|%userprofile%\Start Menu\Programs\Suchmaschinenwelt.lnk
FILEN|%userprofile%\Start Menu\Programs\Tanga.AG.lnk
FILEN|%userprofile%\Start Menu\Programs\Tattoo.lnk
FILEN|%userprofile%\Start Menu\Programs\Tierheime.lnk
FILEN|%userprofile%\Start Menu\Programs\TOP-HUMOR.lnk
FILEN|%userprofile%\Start Menu\Programs\Translator.lnk
FILEN|%userprofile%\Start Menu\Programs\Tuxos.de.lnk
FILEN|%userprofile%\Start Menu\Programs\Vitalinet.de.lnk
FILEN|%userprofile%\Start Menu\Programs\Vorlagen.lnk
FILEN|%userprofile%\Start Menu\Programs\Vornamen.lnk
FILEN|23aw0001.exe
FILEN|arr.exe
FILEN|belgium_sex-uninstall.exe
FILEN|bho.0.1.0.128.dll
FILEN|bho.0.1.0.135.dll
FILEN|crush.exe
FILEN|datemakerintl.exe
FILEN|direktsex.exe
FILEN|freesexx.exe
FILEN|go in.exe
FILEN|handy-paradies.exe
FILEN|hardcoreteens.exe
FILEN|hotsex.exe
FILEN|hotsexvideos.exe
FILEN|hot_canada.exe
FILEN|lolitasex.exe
FILEN|od-stnd24.exe
FILEN|piratos.exe
FILEN|pissing.avi.exe
FILEN|sexy-uninstall.exe
FILEN|sexy_belgium-uninstall.exe
FILEN|syswebtelecomint.dll
NEWPR|2414|VideoDialer
PRCAT|8
DIREC|%ProgramFiles%\hbt\
AUTST|Blondes
AUTST|Hot_Tarts_mc
CLASS|.vmxy
CLASS|vmxy File
RKSOF|hbt
UINST|Hot_Tarts_mc
FILEN|%USERPROFILE%\Desktop\Blondes.lnk
FILEN|%USERPROFILE%\Desktop\Hot_Tarts_mc.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Blondes.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Hot_Tarts_mc.lnk
NEWPR|2506|VividGal
PRCAT|8
NEWPR|411|VLoading
PRCAT|8
CLSIA|{00000000-8633-1405-0b53-2c8830e9faec}
CLSIA|{11bf0e2b-4229-4adc-9c11-1c6968731018}
CLSIA|{67355a47-1544-4905-b698-4d7e5b62ec32}
CLSIA|{91df007c-2f7f-4731-be1f-38c1c13ceb8b}
CLSIA|{ab1e62eb-3de3-428f-a417-64ab3c9b6cf0}
CLSIA|{e44151c8-0c6c-4a7d-b677-4fcc9552e957}
CLASS|econnect.econn
CLASS|VLoading.Download
FILEN|econnect.dll
FILEN|suninfoconnect.dll
FILEN|vloading.cab
FILEN|vloading.dll
NEWPR|3534|W32.Dialer.PornAgent
PRCAT|8
NEWPR|2491|Wild-Flics
PRCAT|8
AUTST|Wild-Flics
FILEN|%USERPROFILE%\Desktop\Wild-Flics.lnk
FILEN|%USERPROFILE%\Start Menu\Wild-Flics.lnk
NEWPR|2226|Win32.Dialer
PRCAT|8
CLSIA|{3d000ecf-1fc1-2c30-c6ac-53494a04b651}
CLSIA|{430bf633-8d63-4891-e908-34d11db86ce4}
CLSIA|{46fba988-a778-6fb8-d917-0da25be4bd7a}
CLSIA|{500080d2-3ef6-4d87-1b30-3d0373d8627b}
CLSIA|{5202e9cd-423b-2813-6a29-3f6232104e67}
CLSIA|{6520eb87-fe23-7aec-0476-6a345e1028c8}
CLSIA|{66c80766-743b-1078-33b0-57926c86edb0}
CLSIA|{7baafd67-98ac-5db9-176e-10d7387c9afa}
DIREC|%WINDIR%\_DlrApps\
AUTST|\windows\syswin.exe
NEWPR|3436|win32.Dialer.gsa
PRCAT|8
NEWPR|801|WinDialer
PRCAT|8
CLSIA|{4bcf322b-9621-4e90-9678-f1424eb7584e}
NEWPR|529|Wonderland
PRCAT|8
CLSIA|{08ee9c58-d8b4-4977-8198-9c771cd8c451}
CLSIA|{0f5b6a38-b470-4446-b453-c248d8fb3a4b}
CLSIA|{6d6ddf37-b491-49d3-8733-600fa16940a0}
CLSIA|{9ddc8f6d-bc51-46cb-b185-ebf34d52a175}
CLSIA|{d06855e1-7758-430f-9e20-274d32c0472e}
CLSIA|{efcf25f1-c8f9-4c53-a03d-68d5c19225d0}
CLASS|Cab33107.Cab_33107
CLASS|WonderPlus.Wonder_Plus
CLASS|WonderWeb.Wonder_Web
FILEN|agrit.exe
FILEN|alberghi.exe
FILEN|cab33107.cab
FILEN|qualsiasi.exe
FILEN|wonderplus.cab
FILEN|wonderplus.ocx
FILEN|wonderplus05.cab
FILEN|wonderplus07.cab
FILEN|wonderplus91.cab
FILEN|wonderplus91.ocx
FILEN|xxlav003.exe
NEWPR|412|X-Diver
PRCAT|8
CLSID|{e17e606a-9836-4619-a249-f40d5d2e812a}
FILEN|xdiver.exe
NEWPR|537|XDialer
PRCAT|8
CLSIA|{1e50b82a-0d78-48b9-97ec-391b2f81ce8a}
CLSIA|{4bf9bc08-8571-4e2b-aecf-ec8c9e287c04}
CLSIA|{69a4f9ff-e915-11d5-a9f1-009099104002}
CLSIA|{8dce908e-9e35-11d3-9431-009099104002}
CLSIA|{9e7138ee-4e7b-11d5-94ef-006008a4ed7f}
CLSIA|{daca803e-b6de-11d4-80e5-0060974b8983}
CLSIA|{e28e4df0-2bca-4904-bcf9-a983e3a80a64}
FILEN|xdial.ocx
NEWPR|2496|XEng004
PRCAT|8
AUTST|DateCheck
NEWPR|2442|Xgen-A
PRCAT|8
CLSIA|{11111111-1111-1111-1111-119357210284}
REGKE|HKEY_CURRENT_USER\dialein2
NEWPR|2589|Xgratos
PRCAT|8
NEWPR|682|XLoader
PRCAT|8
CLSIA|{8c6c6922-6258-44ac-9912-53964ac55272}
CLSIA|{aaaaaaaa-cccc-cccc-dddd-100000000000}
FILEN|xgenius.cab
FILEN|xgenius.exe
FILEN|xgenius.jar
NEWPR|797|Xpehbam Dialer
PRCAT|8
CLSIA|{ad688740-5246-40c3-1111-53959999940d}
CLSIA|{ad688740-5246-40c3-af27-090006046834}
NEWPR|2446|YeakNet
PRCAT|8
DIREC|%APPDATA%\sgrunt\
DIREC|%APPDATA%\tofareraci\
AUTST|oeuai
AUTST|Olympic
IEZON|*.aflashcounter.com
IEZON|1987324.com
IEZON|adslconnection.name
IEZON|sgrunt.biz
IEZON|softlab.name
IEZON|www.1987324.com
IEZON|www.adslconnection.name
IEZON|www.sgrunt.biz
IEZON|www.softlab.name
IEZON|xxx-content.name
NEWPR|1373|Aladino Backdoor
PRCAT|10
AUTST|Regdll32
NEWPR|1372|Almaster
PRCAT|10
FILEN|almaster.exe-34cdc7f0.pf
NEWPR|1425|Alvgus
PRCAT|10
NEWPR|1374|Amanda
PRCAT|10
NEWPR|1375|Arsd Backdoor Installation
PRCAT|10
NEWPR|462|ASpam
PRCAT|10
CLSIA|{499db658-1909-420b-931a-4a8caefd232f}
CLSIA|{657b9354-bb3b-4500-a9b0-109b4fa64815}
NEWPR|2642|B-[R.A.T]-T
PRCAT|10
AUTST|afkasjhfa3254f
RKSOF|BrosTeam
NEWPR|1377|Badboy
PRCAT|10
NEWPR|1380|Birdspy Trojan
PRCAT|10
NEWPR|1381|Blackharaz Trojan
PRCAT|10
NEWPR|1384|Blador.Trojan
PRCAT|10
NEWPR|783|Boss Watcher 1.0
PRCAT|10
RKSOF|Brigsoft
NEWPR|1490|Coma
PRCAT|10
NEWPR|1524|DirectConnection
PRCAT|10
NEWPR|846|FeRAT
PRCAT|10
NEWPR|1593|Freak88
PRCAT|10
NEWPR|936|Hack'a'Tack
PRCAT|10
FILEN|backdoor.hacktack.110.exe
FILEN|backdoor.hacktack.112.exe
FILEN|backdoor.hacktack.120.b.exe
FILEN|backdoor.hacktack.exe
NEWPR|2765|HackAttack
PRCAT|10
NEWPR|905|Hacker Defender
PRCAT|10
NEWPR|2460|Hatr3d F3ind
PRCAT|10
CLASS|FlatButt.FlatButton
NEWPR|1410|Iddono
PRCAT|10
NEWPR|2455|ItADeM
PRCAT|10
NEWPR|1143|Koko Trojan
PRCAT|10
NEWPR|887|LANfiltrator
PRCAT|10
NEWPR|1599|MiniOblivion
PRCAT|10
NEWPR|2468|MsnTroyano
PRCAT|10
AUTST|wini
NEWPR|826|NetBus
PRCAT|10
NEWPR|562|Optix
PRCAT|10
AUTST|GLSetIT32
NEWPR|2704|Osiris
PRCAT|10
NEWPR|2494|Prayer
PRCAT|10
NEWPR|950|Roach
PRCAT|10
NEWPR|1024|ShowPass 1.0
PRCAT|10
NEWPR|2447|Taladrator
PRCAT|10
NEWPR|955|Timbuktu Pro
PRCAT|11
NEWPR|1255|CasinoRewards
PRCAT|15
CLSIA|{ff905e0c-cfe9-4a90-afff-c13af5d908f0}
NEWPR|1028|Ebates Moe Money Maker
PRCAT|15
CLSID|{6685509e-b47b-4f47-8e16-9a5f3a62f683}
CLSID|{7f241c00-dab6-11d5-aaa8-0001028df1bc}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Ebates.
DIREC|%programfiles%\ebatesmoemoneymaker
DIREC|%programfiles%\EbatesMoeMoneyMaker1
DIREC|%programfiles%\EbatesMoeMoneyMaker2
DIREC|%programfiles%\EbatesMoeMoneyMaker3
DIREC|%programfiles%\EbatesMoeMoneyMaker4
DIREC|%programfiles%\Ebates_MoeMoneyMaker
DIREC|%programfiles%\Web Offer
AUTST|djebmm350.exe
AUTST|ebatesmoemoneymaker
AUTST|ebatesmoemoneymaker0
AUTST|ebatessvr2.xml
AUTST|WebSavingsFromEbates0
RKSOF|Ebates
RKSOF|microsoft\internet explorer\menuext\ebates
RKSOF|Web Offer
RKSOF|Web Savings
UINST|ebatesver2.xml
UINST|ebateswebsavings0.xml
UINST|ebateswebsavingsdr0.
FILEN|%ALLUSERSPROFILE%\Start Menu\Programs\Ebates Moe Money Maker\Ebates Moe Money Maker FAQ.lnk
FILEN|disp350.exe
FILEN|eapbh.dll
FILEN|ebatesmoemoneymaker.exe
FILEN|ebatesmoemoneymaker1.exe
FILEN|ebatesmoemoneymaker[1].cab
FILEN|sepng.dll
FILEN|websavingsfromebates.exe
FILEN|websavingsfromebates0.exe
NEWPR|1144|OpinionBar
PRCAT|15
CLSID|{6607c683-ae7c-11d4-acd7-0050dac291a2}
DIREC|%ProgramFiles%\OpinionBar\
DIREC|%USERPROFILE%\Start Menu\Programs\OpinionBar
CLASS|MyIEMonitor.MyIEMonitorObject
RKSOF|UniversalOpinions\OpinionBar
NEWPR|739|Top Moxie
PRCAT|15
CLSIA|{05ce4481-8015-11d3-9811-c4da9f000000}
CLSIA|{0ab5cbcf-6984-4122-bcf7-be33bf5b1cf1}
CLSIA|{1954a4b1-9627-4cf2-a041-58aa2045cb35}
CLSIA|{22e5705c-991a-4646-9053-a9525ca7222a}
CLSIA|{330110a5-f627-4dd7-b0f1-24d09c4da870}
CLSIA|{412f2472-59bc-4ccb-a3d4-c16a7d57cdcf}
CLSIA|{7ef1788a-8c66-4a77-95d2-3341111e4acd}
CLSIA|{9522b3fb-7a2b-4646-8af6-36e7f593073c}
CLSIA|{b7b7eea4-dac2-4e87-a6e8-b583e846389a}
CLSIA|{c6b086d2-146b-47a4-a218-b82dcaf2d872}
CLSIA|{e2cf5c45-7ccc-11d4-9bd1-0080c6f60b6a}
CLSIA|{e389b374-bb5a-4a73-acf4-3ce63e4c1de9}
DIREC|%ProgramFiles%\Care2_GTU\
DIREC|%ProgramFiles%\WebSavingsfromEbates\
DIREC|%ProgramFiles%\Web_Cpr\
AUTST|Care20
AUTST|couponsandoffers
AUTST|WebCpr0
RKSOF|Update Manager
UINST|uncare200
NEWPR|804|WebRebates
PRCAT|15
CLSID|{01fc5803-8644-45d7-877b-5a3924d8ecc4}
CLSID|{03f8822f-8877-4002-8bcd-b532d53d8471}
CLSID|{0a8ce102-fa03-4612-9bee-7fe5452f4cb1}
CLSID|{3d156636-3f7e-46c9-9ac1-5e4d8202aa23}
CLSID|{4eb7bbe8-2e15-424b-9ddb-2cdb9516c2e3}
CLSIA|{7eb15626-cb8e-4174-8a72-c055b12b4310}
CLSID|{bcf96fb4-5f1b-497b-aecc-910304a55011}
CLSID|{f8fb4ea2-6c05-4de5-8cd0-625b03f48e22}
DIREC|%programfiles%\webrebates
DIREC|%programfiles%\WebRebates4\
DIREC|%programfiles%\web_rebates
DIREC|%programfiles%\Web_Rebates\
DIREC|%SystemRoot%\winskw
DIREC|%windir%\bundles
AUTST|%programfiles%\Web_Rebates\
AUTST|blubstersupport
AUTST|untopr11150
AUTST|upromiseremindu
AUTST|webrebates
AUTST|WebRebates0
AUTST|websavingsfromebates
CLASS|ImgConv.clsImgConv
RKSOF|Microsoft\Internet Explorer\MenuExt\Web Rebates.
RKSOF|Web Rebates
UINST|unebmm350
UINST|untopr1150
FILEN|disp1150.exe
FILEN|sahagent-seedcorn1002.exe
FILEN|w11150.exe
FILEN|webrebates.dll
FILEN|webrebates.exe
FILEN|webrebates0.exe
FILEN|webrebates1.exe
FILEN|webrebates2.dll
FILEN|webrebates2.exe
FILEN|webrebatesrun.exe
FILEN|webrebates_auto_installsilent.exe
NEWPR|418|Alexa Toolbar
PRCAT|16
CLSID|{04d79e9f-09a9-4aed-9fc2-6e63a3bca51e}
CLSID|{0a291298-dfb0-4b0d-b547-5a66fd709d57}
CLSID|{0b32bccd-4d64-48eb-8ec3-9ba0807d1349}
CLSID|{0bbb0424-e98e-4405-9a94-481854765c80}
CLSID|{0f3332b5-bc98-48af-9fac-05fec94ebe73}
CLSID|{11b7c44d-3bd8-42a7-aa69-a1bed9723e9c}
CLSID|{1c1f99ea-8b5d-4d08-b6a8-b1e4cb542f9e}
CLSID|{27d784d7-9217-4227-b43b-e06e4781e0cb}
CLSID|{36600c37-fac4-471e-90bb-fc7a9c979c24}
CLSID|{3ceff6cd-6f08-4e4d-bccd-ff7415288c3b}
CLSID|{3df73df8-41e2-4fc2-8cbf-4b9407433755}
CLSID|{3e60160f-0ed6-4dcc-b6b6-850cde4fd217}
CLSID|{3f41980d-b681-488e-9757-0c9744f9c3ce}
CLSID|{446edfee-3a1a-11d3-bd49-00600827885e}
CLSID|{446edfef-3a1a-11d3-bd49-00600827885e}
CLSID|{49160f0d-6be2-4f5f-bcdb-9256da3bb120}
CLSID|{4f7cc126-4cff-4db5-892d-da71a7552c99}
CLSID|{533b5798-12d1-4063-8cd0-ffe842de872d}
CLSID|{547ab549-4dd8-4ea0-b070-f6ea062148ff}
CLSID|{5641f13a-f62e-4326-a5b6-551103ba6272}
CLSID|{57405e21-4f6d-11d3-bd52-00600827885e}
CLSID|{5a9961fd-b0a6-4065-9552-ebfc199683a3}
CLSID|{5cdc7a97-f8e3-4ea6-b0a7-578ecd31de2c}
CLSID|{62e5bcee-2b5f-4866-8b19-197cfacb770c}
CLSID|{68721ce6-c7c1-4c37-ab1f-51644f20b073}
CLSID|{6912beb3-e20c-4953-8c8e-e91b12b55bfc}
CLSIA|{69a72a8a-84ed-4a75-8ce7-263dbef3e5d3}
CLSIA|{6af9bc61-3cc5-42a7-82d1-ffc2562a7289}
CLSID|{6cf4d74b-e6bd-4c8f-83d7-90d6439705b9}
CLSID|{7280333e-17d0-4246-9510-2d6170468585}
CLSID|{738cb0ed-54a7-4061-ae2e-40efd9b1eef6}
CLSID|{79a4d241-de89-11d3-ac85-00c04f2ee811}
CLSID|{7b068023-1ac9-4168-a133-9fdd9361af80}
CLSID|{7bf3a7db-a516-4e24-b40a-f60b34699e26}
CLSID|{7e22206d-52d1-11d4-acb8-00c04f2ee811}
CLSID|{7e22206e-52d1-11d4-acb8-00c04f2ee811}
CLSID|{8561ae3b-1832-471b-ac4f-da479d635b8e}
CLSID|{911a1dfe-c959-11d3-8164-00c04f30faf9}
CLSID|{9af74448-ebd1-484c-8b06-35e597c0b54c}
CLSID|{9bab764b-e4f3-4c7b-99ad-cdf636bbe3a8}
CLSID|{9d74677a-e227-40fb-9511-f7e92ea4083a}
CLSID|{a69107cc-bec8-4a34-b474-211b0f46a764}
CLSID|{a6a08cbd-6673-41b1-b997-3f83a25b45b0}
CLSID|{abf7c4d4-53ef-4c15-8951-d22f63c98e9f}
CLSID|{ac2a5e17-05ed-4e62-86e5-84779e8f0bca}
CLSID|{b3b1d367-4253-42b9-b620-31a7d7710a06}
CLSID|{b71c7d9a-da43-4e8b-bb9b-1684ac2af324}
CLSID|{b79d9232-a798-43db-9e61-281d550460e4}
CLSID|{b7b84995-8b92-46bf-94aa-fa2f3dd23b84}
CLSID|{bcf4d74b-e6bd-4c8f-83d7-90d6439705b9}
CLSID|{c42000c4-703a-4a55-b8af-5c83b24c9922}
CLSID|{c95fe080-8f5d-11d2-a20b-00aa003c157a}
CLSIA|{ca68bdcc-579c-4730-99f5-37c4e206e4f9}
CLSID|{d1f6abee-b889-11d2-8e3c-dcca155f9a71}
CLSIA|{d1f6abef-b889-11d2-8e3c-dcca155f9a71}
CLSID|{d32ea48b-025d-4ced-810b-b2d805478837}
CLSID|{dc21cede-3b81-43d7-b816-daefa7b4901f}
CLSID|{e3978204-d428-11d3-8164-00c04f30faf9}
CLSID|{ea20f195-32da-4bd6-b348-fd01fc7d3d5a}
CLSID|{eacaa5ce-99b3-470e-9629-8f9ef4c4b637}
CLSID|{eccc5b5c-fa9f-42a1-993f-c67a8161f5a0}
CLSID|{f1fabe79-25fc-46de-8c5a-2c6db9d64333}
CLSID|{f88028b4-4523-4ec4-a48e-064db9952f30}
CLSID|{fa77ad79-09cf-41fb-b171-cc856f9e737f}
CLSID|{fb1d5ef1-df31-11d3-ac86-00c04f2ee811}
DIREC|%ProgramFiles%\Alexa Toolbar\
CLASS|alxbw.bblhtml
CLASS|alxbw.bblwnd
CLASS|alxbw.browserwnd
CLASS|AlxTB.BHO
CLASS|bhoalexa.bhoalexa
CLASS|PopMenu.Menu
CLASS|Popup.PopupKiller
RKSOF|Alexa Internet
RKSOF|Alexa Toolbar
UINST|Alexa Toolbar
UINST|Alexa65
FILEN|alexainstaller.exe
NEWPR|2658|DialupRipper
PRCAT|16
NEWPR|488|MarketScore
PRCAT|16
CLSIA|{0bb33da5-94b7-401f-9c0a-eb75fc492b78}
CLSIA|{0f5e63ae-8b1a-11d3-80a4-0050da2d7351}
CLSID|{169c7855-c096-4d45-803b-6441552a7e92}
CLSIA|{22536211-e807-49cd-a24e-a903af91feb1}
CLSIA|{35b7e48b-9d81-4c6c-9578-5fd4f620d886}
CLSIA|{4bbe1e26-8ded-11d4-9635-000086522e52}
CLSIA|{b2c03e2e-2219-4ff9-810a-540aca63f8d9}
CLSID|{f88527e2-a8a7-4227-8683-05cfa4eec511}
AUTST|nscheck
AUTST|OSS
AUTST|OSSProxy
AUTST|RelevantKnowledge
CLASS|Nsconfig.nsBrowserConfig
RKSOF|netsetter
UINST|Marketscore
UINST|{8edf80b6-2926-4737-981f-5fd7ec9bf662}
UINST|{eeb86aef-4a5d-4b75-9d74-f16d438fc286}
FILEN|%systemroot%\system32\rk.bin
FILEN|csloa.dll
FILEN|mksc.exe
FILEN|nsconfig.dll
FILEN|okshook.dll
FILEN|osmim.dll
FILEN|ossproxy.exe
FILEN|rlvknlg.exe
NEWPR|607|NavExcel
PRCAT|16
CLSID|{20f36af3-3486-4bb6-8bcb-f1f8abe74d07}
CLSID|{5aa06644-bc46-4220-a460-47a6eb47c96d}
CLSID|{710bcb5b-8c6c-483e-a4f5-faf083b13184}
CLSIA|{b5ef836b-7582-4d82-9246-17f6c40ddf0f}
CLSIA|{c1e58a84-95b3-4630-b8c2-d06b77b7a0fc}
CLSID|{d80c4e21-c346-4e21-8e64-20746aa20aeb}
CLSID|{fa4de133-d3c3-4ed4-92d1-cd4dde839ab3}
DIREC|%ProgramFiles%\NavExcel Search Toolbar\
DIREC|%programfiles%\NavExcel\
CLASS|NavExcel.NavHelper
CLASS|NHelper.DLL
RKSOF|NavExcel
UINST|NavExcel Search Toolbar
UINST|NavHelper
FILEN|navinst2.ocx
FILEN|nhelper.dll
FILEN|nhupdater.exe
NEWPR|3228|HTTP Tunnel Client
PRCAT|38
DIREC|%AllUsersprofile%\Start Menu\Programs\HTTP-Tunnel
DIREC|%ProgramFiles%\HTTP-Tunnel\
FILEN|%AllUsersprofile%\Desktop\HTTP-Tunnel Client.lnk
FILEN|http-tunnelclient.exe
FILEN|httptunnelinstallerv403065.exe
NEWPR|3227|Proxy based anonymizers
PRCAT|38
NEWPR|3464|ProxyDex
PRCAT|38
NEWPR|3357|Ad Armor
PRCAT|43
DIREC|%ProgramFiles%\Ad Armor\
DIREC|%USERPROFILE%\Start Menu\Programs\Ad Armor\
AUTST|Ad Armor
AUTST|Ad Armor Monitor
AUTST|AdArmor.exe Monitor
RKSOF|Ad Armor
UINST|Ad Armor
FILEN|%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Ad Armor.lnk
FILEN|%USERPROFILE%\Desktop\AdArmor.lnk
FILEN|adarmor.dll
FILEN|adarmor.exe
FILEN|adarmorinstaller.exe
FILEN|adarmor_monitor.exe
FILEN|adarmor_updater.exe
NEWPR|3463|Ad-Purge Adware and Spyware Remover
PRCAT|43
NEWPR|3472|ADS Adware Remover
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\ADS Adware Remover\
DIREC|%programfiles%\ADS Adware Remover\
UINST|ADS Adware Remover_is1
FILEN|%userprofile%\Desktop\ADS Adware Remover.lnk
FILEN|ads adware remover.exe
FILEN|adsremover.exe
NEWPR|2643|Advanced Email Monitoring
PRCAT|43
DIREC|%Programfiles%\Advanced Email Monitoring\
DIREC|%USERPROFILE%\Start Menu\Programs\Advanced Email Monitoring\
UINST|Advanced Email Monitoring
NEWPR|3442|AdwareDeluxe
PRCAT|43
REGKE|HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\alertSpy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\alertSpy.exe
DIREC|%programfiles%\alertSpy\
DIREC|%userprofile%\Start Menu\Programs\alertSpy\
RKSOF|Mandel Enterprises
UINST|alertSpy
FILEN|%userprofile%\Desktop\alertSpy.lnk
FILEN|alertspy.exe
NEWPR|2733|AlfaCleaner
PRCAT|43
REGKE|HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\AlfaCleanerService
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\AlfaCleaner\
DIREC|%APPDATA%\AlfaCleaner\
DIREC|%Programfiles%\AlfaCleaner\
AUTST|AlfaCleaner
UINST|AlfaCleaner.co
m_is1
FILEN|%USERPROFILE%\Desktop\AlfaCleaner.lnk
SERVK|alfacleaner
SERVK|AlfaCleanerService
FILEN|alfacleaner.exe
NEWPR|3323|AntiVermins
PRCAT|43
CLSID|{01775f16-b10c-b483-63e3-afced5dcdef2}
CLSID|{118601e4-0bc8-4b98-aaec-723eba43ed33}
CLSID|{15548c74-5c8b-4911-ae88-739dd473e2ba}
CLSID|{468164cc-476e-47d5-9269-278d0db22a13}
CLSID|{478b7d17-f00a-4ab3-b802-46972cab1ae9}
CLSID|{4fcd9ab0-0765-4117-a612-db3b4fac1ee3}
CLSID|{5d89ba32-c9f8-48cc-b22a-18c808df6d83}
CLSID|{698664ff-f50e-4bdc-b9c0-c00f96a64b84}
CLSID|{823b335c-00de-4886-be7a-fbdc0f69294e}
CLSID|{89ae8b3e-3ee8-4068-8932-60ca9e6ac40b}
CLSID|{93362b42-9631-4bae-92ef-7726e5dd747d}
CLSID|{999e9507-216c-4a7a-b103-57d3ff617e49}
CLSID|{a5a2382e-6ea1-40c9-9eeb-fce758a7a3f1}
CLSID|{c20782a3-b65d-41ab-8d04-bbe3122363c2}
CLSID|{c54890b0-b9f8-4e58-9715-8c58b52a4d5d}
CLSID|{d037be5c-7e06-4d4d-8729-fd1ee7e59c89}
CLSID|{d108017b-1769-4bfb-8a4c-0e6202fdbd08}
CLSID|{decc44f4-e972-4e5c-8f5f-238295c5add5}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiVerminser.exe\
DIREC|%programfiles%\AntiVerminser\
DIREC|%USERPROFILE%\start menu\programs\AntiVerminser\
WINDO|AntiVerminser 2.1
WINDO|AntiVerminser v2.1
AUTST|AntiVerminser
RKSOF|AntiVerminser
UINST|AntiVerminser
FILEN|%APPDATA%\microsoft\internet explorer\quick launch\Antiverminser 2.1.lnk
FILEN|%USERPROFILE%\desktop\AntiVerminser.lnk
FILEN|%USERPROFILE%\start menu\AntiVerminser 2.1.lnk
FILEN|antiverminser.exe
FILEN|av_setup.exe
NEWPR|3495|AntiVirus Protector
PRCAT|43
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusProtection.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Telecom Advance\Antivirus Protection
DIREC|%programfiles%\Antivirus Protection\
DIREC|%userprofile%\Start Menu\Programs\Antivirus Protection\
AUTST|AntivirusProtection
UINST|Antivirus Protection
FILEN|%userprofile%\Desktop\Antivirus Protection.lnk
FILEN|antivirusprotection.exe
NEWPR|3493|Antivirus Solution
PRCAT|43
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusSolution.exe
DIREC|%programfiles%\Antivirus Solution\
DIREC|%userprofile%\Start Menu\Programs\Antivirus Solution\
AUTST|AntivirusSolution
RKSOF|6D Solutions International Inc.
UINST|Antivirus Solution
FILEN|%userprofile%\Desktop\Antivirus Solution.lnk
FILEN|%windir%\system32\filekiller.dll
FILEN|antivirussolution.exe
FILEN|antivirus_solution_setup_1.0.0.exe
NEWPR|2793|BraveSentry
PRCAT|43
DIREC|%programfiles%\BraveSentry\
DIREC|%userprofile%\Start Menu\Programs\BraveSentry\
WINDO|BraveSentry 2.0
AUTST|BraveSentry
RKSOF|BraveSentry
UINST|BraveSentry
FILEN|%userprofile%\Desktop\BraveSentry.lnk
FILEN|bravesentry.exe
FILEN|bravesentry0.dll
FILEN|bravesentry1.dll
FILEN|bravesentry2.dll
FILEN|bravesentry3.dll
FILEN|bravesentrysetup.exe
NEWPR|3552|ContraVirus
PRCAT|43
CLSID|{1be8c6a5-a75f-4e33-89c3-18cc58a0b952}
CLSID|{2c02e5fc-7fe3-4122-911f-829314fe9bbc}
CLSID|{32bd20fd-41fd-47fb-9bc9-28dcbd7d55d7}
CLSID|{61877300-54db-4746-ba42-03e03a2b269c}
CLSID|{63321a5c-d8fe-432c-8d2f-61c0fc264320}
CLSID|{6b677f1f-f86c-4757-bf24-7d865ef20639}
CLSID|{7c11c36c-2ae0-4489-9b09-a6129139d52d}
CLSID|{99a753c6-e429-46bd-989e-dd4a21cd059d}
CLSID|{bbbd3e11-d201-46c9-8471-091d33159287}
CLSID|{bfcbb188-18e3-1deb-59d5-bace1ce655a4}
CLSID|{d2c1986a-fbec-4472-aabf-6d42f08dbc8e}
CLSID|{dbe5bee8-f032-11db-826a-c4bb56d89593}
CLSID|{ea038ddd-0fe0-41f5-ba60-fc3660529e71}
CLSID|{f51bc478-d997-4c56-988d-79d9eeaad1ec}
CLSID|{fd4dcb8b-c33a-4e70-a351-6fab7e1071a4}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\Ad-Protect.Addin.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ad-protect.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ContraVirus.exe
DIREC|%appdata%\AdProtect NoSpam\
DIREC|%programfiles%\ContraVirus\
DIREC|%userprofile%\Start Menu\Programs\ContraVirus\
AUTST|ContraVirus
AUTST|Windows Updater Servc
CLASS|Ad-Protect.Addin
CLASS|IEControl.IEExtension
CLASS|SCToolBand.SCToolBandObj
CLASS|ToolBarNotifier.Notifier
RKSOF|ContraVirus
UINST|ContraVirus
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\ContraVirus 2.0.lnk
FILEN|%temp%\ContraVirus 2.0 Installer.exe
FILEN|%userprofile%\Desktop\ContraVirus 2.0.lnk
FILEN|%userprofile%\Start Menu\ContraVirus 2.0.lnk
FILEN|contravirus.exe
FILEN|contraviruspro.exe
FILEN|cvantispam.dll
FILEN|cv_1_setup.exe
FILEN|desktopmanager.dll
FILEN|secieaddin.dll
FILEN|startupeditor.dll
FILEN|xpuupdate.exe
NEWPR|3575|CurePCSolution
PRCAT|43
CLSID|{2687b107-2b13-410a-a850-be211b74af12}
DIREC|%allusersprofile%\Start Menu\Programs\CurePCSolution\
DIREC|%programfiles%\CurePCSolution\
UINST|{2687B107-2B13-410A-A850-BE211B74AF12}
FILEN|%allusersprofile%\Desktop\Start CurePCSolution.lnk
FILEN|%allusersprofile%\Start Menu\Programs\Startup\Start CurePCSolution.exe.lnk
FILEN|curepcsolution.exe
NEWPR|3150|Drive Cleaner
PRCAT|43
CLSID|{22024dc7-d190-44ec-9d49-aee5f244a466}
CLSIA|{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6}
CLSID|{7ec618f2-c506-4221-9f56-792b92bf762e}
CLSID|{943b96a4-9bf6-42fe-8d0b-4bca71c3632f}
CLSID|{c4c4786c-9861-46d2-bb63-ac782ab07046}
DIREC|%allusersprofile%\Start Menu\Programs\DriveCleaner 2006 Free
DIREC|%programfiles%\DriveCleaner 2006 Free
DIREC|%userprofile%\Local Settings\Temp\UDC6_0001_D19M1908
AUTST|DC6_check
AUTST|DriveCleaner 2006 Free
CLASS|UDCPChk.UDCPChk
CLASS|UDCShell
RKSOF|drivecleaner 2006 free
UINST|UDC6_is1
FILEN|%userprofile%\Desktop\DriveCleaner 2006 Free.lnk
FILEN|udc2006.exe
NEWPR|3511|Error Protector
PRCAT|43
DIREC|%allusersprofile%\Application Data\ErrorProtector Free\
DIREC|%allusersprofile%\Start Menu\ProgramsErrorProtector Unregistered Version\
DIREC|%allusersprofile%\Start Menu\Programs\SystemDoctor 2006 Unregistered Version\
DIREC|%ProgramFiles%\Common Files\ErrorProtector Free\
DIREC|%ProgramFiles%\ErrorProtector Free\
DIREC|%userprofile%\Administrator\Application Data\ErrorProtector Free\
AUTST|ErrorProtector Free
AUTST|pas_check
AUTST|Salestart
AUTST|SystemDoctor 2006 Free
AUTST|USDR6cw
RKSOF|ErrorProtector Free
RKSOF|uIconnoIgenannoIEewnooEwoMcocwhMgewne
FILEN|%userprofile%\Desktop\ErrorProtector.lnk
FILEN|%userprofile%\Desktop\WinAntiVirus Pro 2007.lnk
NEWPR|2740|ErrorSafe
PRCAT|43
CLSID|{05324ed1-05c0-4e3a-a34f-98bfc64426f5}
CLSID|{06170642-fa65-4fb6-ac79-5f235cb99bc2}
CLSID|{0ba379c6-0efd-4a28-932c-d20469052fd9}
CLSID|{0bc09fc7-473d-4f9c-b49b-f4e3e244b47a}
CLSID|{0d146b7f-fa35-465d-b716-bcbc1f9a92d3}
CLSID|{12813770-461e-4a9f-8c5b-c227a8e9fbe8}
CLSID|{1562d24e-f5bf-4bb4-af4c-bbb610b62638}
CLSID|{1640de0e-75e4-4a83-b5d1-2492bc7eba8f}
CLSID|{16deee6b-aefc-4ba6-9f32-57bbe6783a7c}
CLSID|{184b0a26-4c9c-4757-abf5-4b6af71f9a45}
CLSID|{18a41b20-e519-47a1-b545-ffc200730e9b}
CLSID|{196c80cb-20a7-4cf9-9c98-9322fb1e35fb}
CLSID|{1b197c22-561f-455f-8511-35b1a45c5c9f}
CLSID|{21c724d0-b91a-4f35-99e7-55d325f00b20}
CLSID|{250d1063-5414-4fb0-86d5-aabb7a5d7da7}
CLSID|{2a1647e8-3ec2-49fe-b632-e12d765fa0cc}
CLSID|{2b334c22-40ca-438f-913a-61a8105c4ccd}
CLSID|{2decfcc9-d910-4bac-94b8-fc006827a60f}
CLSID|{356af2e9-8874-4c60-a3d8-0cb516c9e747}
CLSID|{35ba68da-a9f5-4374-8b97-1183d93846a4}
CLSID|{43db73eb-4c90-4418-b6ad-10db22016908}
CLSID|{489b338e-e4ab-489a-91d4-69970a541cf9}
CLSID|{4aa76f27-81bc-4c3f-9f24-cb99349c8cc9}
CLSID|{4f4e2384-42ad-4fe4-b966-b6d50c7bf90a}
CLSID|{5284ac2a-ef00-4750-9b82-b5b907d26536}
CLSID|{59399e33-fb54-48ab-8ae4-ae108b36dab4}
CLSID|{5e19dee2-8d2f-4a9c-a66d-76bbeedd15cb}
CLSID|{5eed48aa-f20f-4085-b8f8-57724b7c5b08}
CLSID|{647b8364-79e0-48e2-a4ca-233abada0c2d}
CLSID|{6813bffd-be81-4613-b4e6-aa7ed0da8659}
CLSID|{68bc55e9-4d3e-4c89-89ac-7559763c98b8}
CLSID|{692ca430-32c8-470d-ba1f-7e15e21e7043}
CLSID|{6ae7418b-229f-4a2c-ae1b-d5962888f02d}
CLSID|{77ca442a-0c72-492b-804a-82611e558142}
CLSID|{7ca36000-3320-49d1-bad1-4c5169d4084a}
CLSID|{7d435027-f646-4bf9-b2c5-0ef4940d5ca2}
CLSID|{7e73c9db-69fb-4580-8e8e-194b34a2306c}
CLSID|{7e7a1949-5c0c-45f3-a106-34fe038493ef}
CLSID|{7f4e63c9-f30c-4424-9baf-b6896f5f56c4}
CLSID|{7fa4ec26-6a28-4474-857d-bb05b001c84a}
CLSID|{8dae9202-0019-4d30-a5d2-aaf02d4ddc37}
CLSID|{8ecc09e1-634b-42ac-8be7-e6edbb53c90e}
CLSID|{94dbdb63-5f05-4c51-8b14-de0ca12ef4ca}
CLSID|{965a8d33-ae18-4c17-8011-fe42d81e0758}
CLSID|{96d58666-8f00-4a9d-9389-c17aaa2407c9}
CLSID|{9dd86cf2-8ac0-4fe0-b55a-601a302b5fd8}
CLSID|{9e87077c-380c-407d-8dab-eedad95c0a5d}
CLSID|{a0e2e5ab-c02f-489b-bd7b-58c329f774f3}
CLSID|{a92616b1-2e82-4052-b579-0a40c2304380}
CLSID|{ae4026cc-b7ba-48e8-8fb3-2c35099670a1}
CLSID|{b0f4bc0f-eaea-43b5-8ce6-dad3cc9b29a2}
CLSID|{b869788c-35df-4104-bacb-8fdb83affffd}
CLSID|{bd9421bb-9f96-4272-802f-49bec746056e}
CLSID|{c033567c-68fe-419b-bcc4-135db7faf8eb}
CLSID|{c7efdcde-a181-41d0-a551-16f73b398040}
CLSID|{c833a552-f5af-4a7b-87b3-6ebde0db3b43}
CLSID|{c85a4afd-ff76-4661-b76a-3e9bb2ce2dab}
CLSID|{cf5c9fce-c963-49e5-a3a4-0a81fffe1e55}
CLSID|{d090e12d-b79c-4b82-a76c-0e3bbe73c9ef}
CLSID|{d80a56d7-451c-41cf-9a74-1447e0887b97}
CLSID|{e0110779-5f79-4685-9c96-9d99efd30ca2}
CLSID|{e73e3959-fb15-44d7-acb9-3a75377006fc}
ID|{e79d5e54-81c9-41ae-9d7b-03f1e5a7733d}
CLSID|{e7ccbd19-2eea-4b6a-b9be-e8a68613809c}
CLSID|{ea0f107f-2bf6-44a0-96c4-a99b74afbc4a}
CLSID|{edf78e1b-31a2-4c6e-ad40-0afcd0d55263}
CLSID|{f585cb1f-f17d-4007-a573-b663197ef500}
CLSID|{f5ab293c-2e21-4441-9ad8-b3646eb26df5}
CLSID|{f5ac8b35-5b15-4e8f-8046-43858973b495}
CLSID|{f63e3b76-f82f-46eb-851c-8c0a221686bb}
CLSID|{f709f572-86f5-47c8-afcf-3cebc468fadb}
CLSID|{f874a0ae-66e8-426b-a3f5-6ba6958dcdba}
CLSID|{f97e5b38-4887-444a-86f5-91c18331500b}
DIREC|
%AllUsersprofile%\Start Menu\Programs\Error Safe\
DIREC|%AllUsersprofile%\Start Menu\Programs\Error Safe Unregistered Version\
DIREC|%AllUsersprofile%\Start Menu\Programs\ErrorSafe\
DIREC|%CommonProgramFiles%\Error Safe\
DIREC|%CommonProgramFiles%\ErrorSafe\
DIREC|%ProgramFiles%\Common Files\ErrorSafe\
DIREC|%ProgramFiles%\Error Safe Free\
DIREC|%ProgramFiles%\errorsafe\
AUTST|Error Safe
AUTST|ErrorSafe
AUTST|ERScw
AUTST|was6_check
CLASS|CompCleanCore.CCQuickScan
CLASS|CompCleanCore.InetCleaner
CLASS|CompCleanCore.RegCleaner
CLASS|CompCleanCore.SystemCleaner
CLASS|df_proxy.DriverManipulate
CLASS|ESCompCleanCore.ESAppCleaner
CLASS|ESCompCleanCore.ESCCQuickScan
CLASS|ESCompCleanCore.ESFileCleaner
CLASS|ESCompCleanCore.ESInetCleaner
CLASS|ESCompCleanCore.ESRegCleaner
CLASS|ESCompCleanCore.ESSystemCleaner
CLASS|ESdf_fixer.ESFixer
CLASS|ESdf_proxy.ESDriverManipulate
CLASS|ESFFWraper.ESFFEnginWraper
CLASS|ESFixCore.ESMMFixCore
CLASS|ESMMFixCtrl.ESCoFixEngine
CLASS|ESSPChck.ESSPChck
CLASS|ESSPCheck.ESSPCheck
CLASS|FlFxr15.FlFixer15
CLASS|FlFxr5.FlFixer5
CLASS|FWraper.FFEnginWraper
CLASS|FxCore.MMFixCore
CLASS|MMFixCtrl.CoFixEngine
CLASS|MMFxCtrl.CoFixEngine
RKSOF|error safe
RKSOF|Error Safe Free
RKSOF|ErrorSafe
UINST|ERS_is1
FILEN|%userprofile%\Desktop\Error Safe.lnk
FILEN|%userprofile%\Desktop\ErrorSafe.lnk
IEZON|errorsafe.com
NEWPR|3531|ExpertAntivirus
PRCAT|43
CLSID|{16dd131d-c09f-4f83-a1e7-a2cf506ea27c}
CLSID|{3e67e9dc-7294-44c3-bc99-ea6e29e74076}
CLSID|{69ebf0db-f6b5-4479-8352-aa632f522d34}
CLSID|{7c1530bd-16b0-41a9-b428-17ee8cbd3e06}
CLSID|{9ec61371-c3b9-fcc1-ee6f-2e4e8d12dffc}
CLSID|{b60f5afa-edd2-417d-a438-57f3ebd9e639}
CLSID|{d59b2dd5-0609-4bdc-ab47-a9a28abc482a}
CLSID|{f82fd7d4-2ec8-40b3-a141-de051c98dce9}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\ExpertAntivirus.Addin.1
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\AdLoader
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Trace7
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\1das\AdLoader
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\dnl7\tracer
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ExpertAntivirus.exe
DIREC|%programfiles%\ExpertAntivirus\
DIREC|%userprofile%\Start Menu\Programs\ExpertAntivirus\
AUTST|ExpertAntivirus
CLASS|ad-protect.EXE
CLASS|ExpertAntivirus.Addin
CLASS|spamdet.DLL
RKSOF|ExpertAntivirus
UINST|ExpertAntivirus
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\ExpertAntivirus v4.1.lnk
FILEN|%userprofile%\Desktop\ExpertAntivirus v4.1.lnk
FILEN|%userprofile%\Start Menu\ExpertAntivirus v4.1.lnk
FILEN|expertantivirus.exe
NEWPR|3501|Fixer AntiSpy
PRCAT|43
DIREC|%programfiles%\Fixer Antispy\
DIREC|%userprofile%\Start Menu\Programs\Fixer Antispy\
AUTST|Fixer Antispy
AUTST|Fixer Antispy Monitor
AUTST|FixerAntispy.exe Monitor
RKSOF|Fixer Antispy
UINST|Fixer Antispy
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\Fixer Antispy.lnk
FILEN|%userprofile%\Desktop\FixerAntispy.lnk
FILEN|fixerantispy.dll
FILEN|fixerantispy.exe
FILEN|fixerantispyinstaller.exe
FILEN|fixerantispy_monitor.exe
FILEN|fixerantispy_updater.exe
NEWPR|3546|Internet Cleanup
PRCAT|43
NEWPR|3107|Kill and Clean
PRCAT|43
CLSID|{4e7883b0-585a-21e2-4dd9-fa16c4875b8c}
CLSID|{bf69df00-2734-477f-8257-27cd04f88779}
DIREC|%ProgramFiles%\KillAndClean
RKSOF|killandclean
UINST|killandclean
FILEN|%USERPROFILE%\desktop\Kill & Clean Scanner and Monitor.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\KillAndClean
FILEN|killandclean.exe
FILEN|killandcleansetup.exe
FILEN|killandcleanupdate.exe
NEWPR|3513|Malware Stopper
PRCAT|43
DIREC|%programfiles%\MalwareStopper\
DIREC|%userprofile%\Start Menu\Programs\MalwareStopper\
AUTST|MalwareStopper
RKSOF|MalwareStopper
UINST|MalwareStopper
FILEN|%userprofile%\Desktop\MalwareStopper.lnk
FILEN|malwarestopper.exe
FILEN|malwarestoppersetup.exe
NEWPR|3305|MalwareWipe
PRCAT|43
NEWPR|2824|MyCleanerPc
PRCAT|43
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\myCleanerPC
DIREC|%allusersprofile%\Application Data\myCleanerPC\
DIREC|%ProgramFiles%\myCleanerPC\
DIREC|%userprofile%\Start Menu\Programs\myCleanerPC\
AUTST|myCleanerPC
RKSOF|VB and VBA Program Settings\MyCleanerPC
RKSOF|VB and VBA Program Settings\MyCleanerPC\Settings
UINST|myCleanerPC
NEWPR|3577|NeoSpace
PRCAT|43
DIREC|%programfiles%\Neospace\
DIREC|%userprofile%\Start Menu\Programs\Internet Security\
RKSOF|Neospace
UINST|Internet Security
FILEN|%userprofile%\Desktop\Internet Security.lnk
FILEN|isec30.exe
NEWPR|3419|PerfectCleaner
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\PerfectCleaner\
DIREC|%programfiles%\PerfectCleaner\
AUTST|PerfectCleaner
RKSOF|PerfectCleaner
UINST|PerfectCleaner
FILEN|%allusersprofile%\Desktop\PerfectCleaner.lnk
FILEN|perfectcleaner.exe
FILEN|perfectcleaner_setup.exe
NEWPR|2853|Pest Trap
PRCAT|43
DIREC|%programfiles%\PestTrap\
WINDO|PestTrap Control Panel
AUTST|PestTrap
RKSOF|PestTrap
UINST|PestTrap
NEWPR|3581|PestBot
PRCAT|43
REGKE|HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\Pestbot
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Pestbot.exe
DIREC|%programfiles%\Pestbot\
DIREC|%userprofile%\Start Menu\Programs\Pestbot\
AUTST|Pestbot
RKSOF|Mandel Enterprise
FILEN|%userprofile%\Desktop\Pestbot.lnk
FILEN|pestbot.exe
NEWPR|3334|PestCapture
PRCAT|43
DIREC|%ProgramFiles%\PestCapture\
DIREC|%USERPROFILE%\start menu\Programs\PestCapture\
WINDO|PestCapture 3.2
AUTST|PestCapture
RKSOF|Install
RKSOF|PestCapture
UINST|PestCapture
FILEN|%USERPROFILE%\desktop\PestCapture.lnk
FILEN|pestcapture.exe
FILEN|pestcapturesetup.exe
NEWPR|2860|Privacy Defender
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\Privacy Defender v4.0\
DIREC|%ProgramFiles%\PrvDef4.0\
UINST|Privacy Defender v4.0
NEWPR|2870|PSGuard
PRCAT|43
CLSID|{01c9453d-0004-43a5-ab44-6aa307c2a0aa}
CLSID|{0bc3bcd5-476d-4be3-a9b9-2225e1b96e90}
CLSID|{1038b941-451a-4a73-b5c0-a9b3243acfbe}
CLSID|{132698d9-0cd6-45e6-8c3f-aa7080a181a1}
CLSID|{15dc7116-e58e-4395-a45a-a1c99b17c030}
CLSID|{17e02586-a91d-4a9d-a74e-187b05dffe6f}
CLSID|{1b1c94e1-cc70-4824-80db-dd7274a66ff1}
CLSID|{1bd98dfd-2da9-4c54-85d7-be03a0f9c487}
CLSID|{1c94ea51-3800-4f08-b5dc-a5b67823ffea}
CLSID|{20d1af34-6e19-42d8-af9f-bdfbe45c2454}
CLSID|{21e132c9-1f98-4151-bdad-7d9b49c60a8e}
CLSID|{23f7ad29-f51a-4ba1-be70-143b1cb25bd1}
CLSID|{28fedb90-53c7-4928-994a-cee782606507}
CLSID|{2c462d06-3ba0-48bb-9282-bb6519fe86e9}
CLSID|{2c59d5ec-6b91-4896-bd6f-5f121d87a7f8}
CLSID|{2f34e0e0-f0bb-477f-afb8-509262fa0ad1}
CLSID|{35ed274e-3f42-4a78-bbdc-3b7d73e85578}
CLSID|{3a350193-c7f7-4e10-b347-02ff4c3cc4e9}
CLSID|{3d74d140-f780-4ae3-8d6d-f8dc39107213}
CLSID|{4723879b-8f52-4be7-9994-626afa539366}
CLSID|{49443d6e-ce4e-47a9-8deb-f5774ce14984}
CLSID|{52034ad2-914c-4634-b375-9299631e5525}
CLSID|{7702c521-76ae-42c0-a181-3b5a96c2eef7}
CLSID|{7adda344-1d36-4446-9f4b-b2351fb19efd}
CLSID|{7b6a3434-8625-4abf-b79d-09d98c2498c4}
CLSID|{7d98221e-af8f-4d29-8bb1-1dfabc288173}
CLSID|{8b6c0168-baac-4c7c-911e-0132590f5661}
CLSID|{8ec33b7d-9953-4edb-ace2-d4c105968601}
CLSID|{9746b450-6064-4ec8-9480-72a289aa2237}
CLSID|{982392f9-9c65-48b4-b667-3459c46630d1}
CLSID|{a00e2305-7001-4200-ba00-5779f9a3e7d3}
CLSID|{a20f5672-7486-4d27-bd2b-e555e4692c5f}
CLSID|{a4b6a8ab-01c1-4f9d-abe1-11a0a574d987}
CLSID|{a917b2f3-a9bf-477c-a0e3-0382d0376159}
CLSID|{b26b5883-f15f-4283-b3d5-a1728077de47}
CLSID|{b803d266-a08d-4a4c-9604-6d35689abe09}
CLSID|{c5a40fce-0a0f-40ca-985e-661c28b5b431}
CLSID|{c6e2a22c-b3a8-43a4-b5ec-a5bb671ab3f7}
CLSID|{c7f22879-7151-4c71-8c50-9557afda66c6}
CLSID|{ca5e7959-60b5-47b7-80ac-1606309733f3}
CLSID|{cabd3101-8501-45b0-928f-86086d66b4b8}
CLSID|{cb9385ab-8541-4b2f-a363-48f64c612993}
CLSID|{ceabf027-6cdc-4d47-adf6-ac5d065826a6}
CLSID|{cf1674cc-ec9a-4aee-996e-65a8f7c0b0e4}
CLSID|{d5d6e9b5-30d5-4457-ac8b-399205f50411}
CLSID|{d6a7d177-0b2f-4283-b2e8-b6310a45e606}
CLSID|{e0aa0493-c410-4cbd-b1db-1723374fa8e0}
CLSID|{e0d6c30a-b9a3-4181-8099-3b0d5a2b98af}
CLSID|{e2605a54-ec78-4618-83d8-bfef45bf370b}
CLSID|{e5d78bd8-3874-4aa0-9d45-cfb79382c484}
CLSID|{e68572c0-6051-4ace-93d3-9981f91da24f}
CLSID|{f100a342-3ac5-47ff-b5b3-fcdb6fc9f016}
CLSID|{f4364eec-31f5-4b8b-a7e0-3b6394c9d23f}
CLSID|{f61d1ce1-5199-4b57-b59e-c6819ea92f3b}
DIREC|%APPDATA%\shudder global limited\psguard\
DIREC|%programfiles%\PSGuard\
RKSOF|ShudderLTD
NEWPR|3540|RegFreeze
CAT|43
CLSID|{635cb2d1-772c-4fcc-af87-ef6c316c9a5a}
CLSID|{76044441-36ea-4e99-a71a-c12070dd13cd}
CLSID|{cdb280e8-be43-4128-8a5a-3fcd094e2d88}
CLSID|{f745f808-e783-4301-8b95-253dc70beefe}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FindExtensions\Static\RegFreeze
CLASS|rfsearchhandler.DLL
CLASS|rfsearchhandler.RegFreezeIEButton
CLASS|rfsearchhandler.RegFreezeSearchHandle
CLASS|rfsearchhandler.RegFreezeSearchHandler
RKSOF|ActualResearch
RKSOF|ADV
UINST|RegFreeze_is1
FILEN|regfreeze.exe
FILEN|rfsearchhandler.dll
NEWPR|2772|Spy-Shield
PRCAT|43
CLSID|{4c824d74-1df5-4058-bd78-203774f09930}
CLSID|{c628512d-a058-4bd4-b47b-b036f45fa02b}
CLSID|{d7abe914-b8cf-4602-9145-6bdaaeda21aa}
CLSID|{df831c0c-f9bc-4e43-8cf4-538f8230e337}
CLSID|{dfcda823-80c5-4f55-b328-7efd4afbd9a0}
CLSID|{ee58659d-4af6-407e-8c88-2f1f45ff8cbd}
REGKE|HKEY_CLASSES_ROOT\AppID\ad-protect.EXE
REGKE|HKEY_CLASSES_ROOT\AppID\spamdet.DLL
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\Spy-Shield.Addin.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Spy-Shield.exe
DIREC|%ProgramFiles%\Spy-Shield\
DIREC|%UserProfile%\Start Menu\Programs\Spy-Shield\
AUTST|Spy-Shield
CLASS|Ad-Protect.Server
CLASS|spamdet.SpamDetector
CLASS|Spy-Shield.Addin
RKSOF|SpyShield
UINST|Spy-Shield
FILEN|%AppData%\Microsoft\Internet Explorer\Quick Launch\Spy-Shield v4.1.lnk
FILEN|%USERPROFILE%\Desktop\Spy-Shield v4.1.lnk
FILEN|%USERPROFILE%\Start Menu\Spy-Shield v4.1.lnk
NEWPR|3425|SpyAway
PRCAT|43
CLSID|{4f65d192-327b-41d6-b082-0d2a104d9b73}
CLSID|{8dd59a91-90a4-4182-8bb5-d545bb5e766f}
CLSID|{d815e42a-0e0b-44b1-8f48-b2e1adbfc3e1}
DIREC|%allusersprofile%\Start Menu\Programs\SpyAway\
DIREC|%programfiles%\SpyAway\
AUTST|SpyAway
CLASS|sa_ie_monitor.ie_monitor
RKSOF|AntiSpyware InstalledApplication
RKSOF|spyaway
UINST|SpyAway
FILEN|%allusersprofile%\Desktop\SpyAway.lnk
FILEN|sa_ie_monitor.dll
FILEN|spyaway.exe
FILEN|spyaway_setup.exe
NEWPR|2361|Spyaxe
PRCAT|43
CLSID|{11853d5f-f894-4cc7-bbc3-fc7a9dcfd896}
CLSID|{2bb3bcbf-411a-4c67-8e69-f4bb301dc333}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\SpyAxe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\SpyAxe.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\spyaxe.exe
DIREC|%programfiles%\SpyAxe\
DIREC|%userprofile%\Start Menu\Programs\SpyAxe\
AUTST|SpyAxe
CLASS|SpyAxe.Backup
CLASS|SpyAxe.EngineListener
CLASS|SpyAxe.Log
CLASS|SpyAxe.LogRecord
CLASS|SpyAxe.Paths
CLASS|SpyAxe.Quarantine
CLASS|SpyAxe.RunAs
CLASS|SpyAxe.Scanner
CLASS|SpyAxe.SearchItem
CLASS|SpyAxe.ThreatCollection
UINST|SpyAxe
FILEN|%userprofile%\Desktop\SpyAxe.lnk
NEWPR|2127|Spybouncer
PRCAT|43
CLSID|{1a0a00f0-3ffe-4e88-944e-3cc8cd1eb3eb}
CLSID|{26b72764-a203-4f29-88e1-8cbc06d2051c}
CLSIA|{4fa3d392-9349-4d85-8fb9-18733534cfe3}
CLSIA|{5e8fd788-c323-4357-ab76-7cbcefba573c}
CLSID|{651d03f0-2655-4d98-a41a-c8d76ad8a1f4}
CLSIA|{7d40adf2-ad68-4959-acec-da96bf5e6eb7}
CLSID|{9a7ef0e4-86f7-41ae-87d3-bfaffcf597e0}
CLSID|{d5515c94-7fe6-4602-8ac9-8e854ba1b766}
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\SpyBouncer\
CLASS|SpyBouncer.SBDownloader
FILEN|%ALLUSERsPROFILE%\Desktop\SpyBouncer.lnk
FILEN|%ALLUSERSPROFILE%\Start Menu\SpyBouncer.lnk
NEWPR|2847|SpyContra
PRCAT|43
DIREC|%ProgramFiles%\SpyContra\
RKSOF|XXI
UINST|SpyContra
NEWPR|3383|Spycrush
PRCAT|43
DIREC|%programfiles%\SpyCrush\
DIREC|%userprofile%\Start Menu\Programs\Spycrush\
AUTST|SpyCrush
RKSOF|Spycrush
UINST|spycrush
FILEN|%userprofile%\desktop\spycrush.lnk
FILEN|%userprofile%\Start Menu\Spycrush 5.1.lnk
FILEN|spycrush.exe
NEWPR|3366|SpyDawn
PRCAT|43
CLSID|{189518df-7eba-4d31-a7e1-73b5bb60e8d5}
CLSID|{2016a466-91a2-43c6-97d8-2fd380f065ef}
CLSID|{23d627fe-3f02-44cf-9ee1-7b9e44bd9e13}
CLSID|{43cfefbe-8ae4-400e-bbe4-a2b61bb140fb}
CLSID|{5790b963-23c5-43c1-bcf5-01c9b5a3e44e}
CLSID|{661173ee-fa31-4769-97d4-b556b5d09bda}
CLSID|{76d06077-d5d3-40ca-b32d-6a67a7ff3f06}
CLSID|{8329660f-e248-4872-98cc-fb9c4fec7ba8}
CLSID|{86c7e6c3-ec47-44e5-aa08-ee0d0a25895f}
CLSID|{9283dac1-43f5-4580-bf86-841f22af2335}
CLSID|{9d635a36-6b3c-4146-8625-f3aaf507bbf8}
CLSID|{ae90cafc-09d4-47f0-9e11-ce621c424f08}
CLSID|{ba397e39-f67f-423f-bc6e-65939450093a}
CLSID|{bec8a83d-01d4-4f15-b8a9-4b4ab24253a7}
CLSID|{c1df2728-8510-0773-96d8-5d0c1f27821b}
CLSID|{c4eedc19-992d-409a-b323-ed57d511afa5}
CLSID|{dd90f677-d205-4f70-9014-659614aabcb2}
CLSID|{e3df91f3-f24f-441e-9001-d61f36024322}
CLSID|{f459eadb-5903-48d5-864c-2b7b46ab1424}
CLSID|{fc4edf66-0547-4f1a-ae96-7cfcad711c90}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyDawn.exe
DIREC|%programfiles%\SpyDawn\
DIREC|%userprofile%\Start Menu\Programs\SpyDawn\
DIREC|%userprofile%\Start Menu\SpyDawn 3.1.lnk
AUTST|didynamia
AUTST|eitheror
AUTST|flammei
AUTST|SpyDawn
RKSOF|SpyDawn
UINST|SpyDawn
FILEN|%APPDATA%\Microsoft\Internet Explorer\Quick Launch\SpyDawn 3.1.lnk
FILEN|%userprofile%\Desktop\SpyDawn.lnk
FILEN|higehsg.dll
FILEN|spydawn.exe
FILEN|xkrdk.dll
NEWPR|2734|SpyFalcon
PRCAT|43
CLSID|{008e3200-28eb-463b-9b58-75c23d80911a}
CLSID|{244b730e-d899-4e38-9428-03d1143242e0}
CLSID|{330a77c2-c15a-43b5-055c-b4e35eaed279}
CLSID|{7a932ed2-1737-4ab8-b84d-c71779958551}
CLSID|{b4e17829-dacb-4320-9abf-dcb382221fc2}
CLSID|{d1a2e7cd-f5c1-21a8-ca2c-13d0ac72d19d}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyFalcon.exe
DIREC|%ProgramFiles%\SpyFalcon\
DIREC|%USERPROFILE%\Start Menu\Programs\SpyFalcon\
AUTST|SpyFalcon
UINST|SpyFalcon
FILEN|%userprofile%\Desktop\SpyFalcon.lnk
FILEN|%userprofile%\Start Menu\SpyFalcon 2.0.lnk
FILEN|atmclk.exe
FILEN|spyfalcon.exe
NEWPR|3426|SpyFighter
PRCAT|43
DIREC|%programfiles%\SpyFighterPro\
DIREC|%userprofile%\Start Menu\Programs\Spy Fighter Pro\
NEWPR|3564|SpyHazard
PRCAT|43
CLSID|{38de4854-bafb-4dff-ae9c-7d6759e1c0a6}
CLSID|{3a4018fd-2a09-4b21-83a0-6f8091f65033}
CLSID|{4a88d502-e8ff-5de6-0799-c215f685c7df}
CLSID|{4c88865f-3df8-4d34-ba45-00e06c12e115}
CLSID|{5af3a36c-3e0f-46bb-b537-7c00c2b86844}
CLSID|{6f0d21e5-07d1-48db-b2a5-4b64f9efd18a}
CLSID|{77947400-c626-4e6b-ba99-9bb374a91993}
CLSID|{86e1cfb9-abe5-467a-895f-c12a121044f8}
CLSID|{88c0cc0d-c111-4025-a35f-f4342ea00d2b}
CLSID|{99acbdc1-b9ae-4841-a892-786099e4958c}
CLSID|{a1cf0bd5-b707-405c-b2b3-57f0de58f4ba}
CLSID|{a6866a37-2485-42a9-acc6-3f1510b56c5f}
CLSID|{a7893ca6-8646-4014-bdb0-dd259b8d01fd}
CLSID|{af0e923a-c1c0-4d81-8c9d-099a3b049383}
CLSID|{d229d3c6-36b8-4459-859c-b00dd467f138}
CLSID|{dcd0837a-79d7-40ff-82cb-6b07204c8fcb}
CLSID|{e05fb96f-5ea9-46de-94b6-d72590d762b5}
CLSID|{e4c445e1-91bc-4152-aa09-54f2553e3a07}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHazard.exe
DIREC|%programfiles%\SpyHazard\
DIREC|%userprofile%\Start Menu\Programs\SpyHazard\
AUTST|SpyHazard
RKSOF|SpyHazard
UINST|SpyHazard
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\SpyHazard 3.1.lnk
FILEN|%userprofile%\SpyHazard.lnk
FILEN|%userprofile%\Start Menu\SpyHazard 3.1.lnk
FILEN|spyhazard.exe
NEWPR|3027|SpyHeal
PRCAT|43
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHeal.exe
DIREC|%ProgramFiles%\SpyHeal\
DIREC|%UserProfile%\Start Menu\Programs\SpyHeal\
AUTST|%userprofile%\Desktop\SpyHeal.lnk
AUTST|SpyHeal
RKSOF|SpyHeal
UINST|SpyHeal
NEWPR|3328|SpyMarshal
PRCAT|43
DIREC|%programfiles%\SpyMarshal\
DIREC|%USERPROFILE%\start menu\programs\SpyMarshal\
WINDO|SpyMarshal 3.2
AUTST|SpyMarshal
RKSOF|SpyMarshal
UINST|SpyMarshal
FILEN|%USERPROFILE%\desktop\SpyMarshal.lnk
FILEN|spymarshal.exe
NEWPR|2852|SpyOnThis
PRCAT|43
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\SpyOnThis\
DIREC|%ProgramFiles%\SpyOnThis\
AUTST|SpyOnThis Monitor
UINST|{B72A13A7-CCCD-407A-882B-4CFC2ADD39EF}_is1
FILEN|%USERPROFILE%\Desktop\SpyOnThis Monitor.lnk
FILEN|%USERPROFILE%\Desktop\SpyOnThis Scanner.lnk
NEWPR|3330|SpySoldier
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\SpySoldier\
DIREC|%ProgramFiles%\SpySoldier\
AUTST|SpySoldier
UINST|SpySoldier_is1
FILEN|%APPDATA%\Microsoft\Internet Explorer\Quick Launch\SpySoldier.lnk
FILEN|%USERPROFILE%\desktop\SpySoldier.lnk
FILEN|%USERPROFILE%\Local Settings\Application Data\SpySoldier
FILEN|spysoldier.exe
FILEN|spysoldier_setup.exe
NEWPR|2692|SpySpotter
PRCAT|43
DIREC|%ProgramFiles%\SpySpotter3\
DIREC|%ProgramFiles%\SpySpotter\
AUTST|SpySpotter
RKSOF|SpySpotter
UINST|SpySpotter
FILEN|%userprofile%\Desktop\SpySpotter.lnk
FILEN|%Userprofile%\Start Menu\Programs\SpySpotter.lnk
FILEN|%userprofile%\Start Menu\SpySpotter.lnk
NEWPR|3569|SpyVampire
PRCAT|43
DIREC|
%userprofile%\Start Menu\Programs\SpyVampire\
DIREC|%programfiles%\SpyVampire\
AUTST|SpyVampire
RKSOF|SpyVampire
UINST|SpyVampire
FILEN|%userprofile%\Start Menu\programs\SpyVampire.lnk
FILEN|spyvampire.exe
FILEN|spyvampire_1.0.1.311_install.exe
NEWPR|2809|Spyware Cleaner
PRCAT|43
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Spyware Cleaner
DIREC|%programfiles%
\Spyware Cleaner\
DIREC|%userprofile%\start menu\programs\Spyware Cleaner\
AUTST|spyclean
RKSOF|SpywareCleaner
UINST|SpywareCleaner
FILEN|%userprofile%\Desktop\SCFree.exe
FILEN|%userprofile%\SCFree.exe
FILEN|spyclean.exe
FILEN|spywinclean.exe
NEWPR|2806|Spyware Quake
PRCAT|43
CLSIA|{00000000-0000-0000-0000-100000000002}
CLSID|{192c5b4a-3efd-40c7-9f99-c472deb8efc0}
CLSID|{1da7dbe8-c51b-4ae4-bc6e-21863349b0b4}
CLSID|{2dd8d482-8f1c-4180-aa8e-9d5819e5f2ea}
CLSID|{411f83b1-a0ec-4155-af99-0137f5efb270}
CLSID|{4e3645af-7a81-4f83-9b8c-1e4f930d873f}
CLSID|{5753791b-f607-48ca-814e-91c14d081f9e}
CLSID|{5b55c4e3-c179-ba0b-b4fd-f2db862d6202}
CLSID|{5e05ea9f-1ea7-4d0b-a09b-d5e29ec758b9}
CLSID|{61032a65-2371-4c89-b5bb-df73090fb5ea}
CLSID|{66189af2-7726-46e8-8628-0f95ab854792}
CLSID|{7070a8f9-08a4-ca47-0ab0-1eb9e4ee1f3b}
CLSID|{7a2f6251-6c99-4da5-9827-954eb45dcb82}
CLSID|{7b4d79df-9ef0-429d-a0e9-d9b138c6a53b}
CLSID|{82c6c396-dd7b-4ce5-b668-c0087d1f3a1f}
CLSID|{853e0d78-f4c2-47cb-a3f5-a774da60dfcd}
CLSID|{860c2f6b-ca82-4282-9187-beccbb66f0af}
CLSID|{89923a78-1dea-41dc-a323-88da2de7b5ae}
CLSID|{8aed5df3-6e0b-4930-b1a5-f8aa8d757497}
CLSID|{94786c47-eb3f-4bd5-a66b-0d49e2c90541}
CLSID|{9989a9bc-9828-467e-af06-e3b279e6e97b}
CLSID|{b2b3702a-5425-489e-a3af-edccafeba019}
CLSID|{c1c56112-2b2e-4d3c-8cfc-7e10c77facef}
CLSID|{ca14ee13-ed15-c4a2-17ff-da4d15c1bc5e}
CLSID|{cd5e2ac9-25ce-a1c5-d1e2-dc6b28a6ed5a}
CLSID|{d01d4aab-22c5-427f-a941-c4b65a3d8a23}
CLSID|{ddb0d689-fae0-4165-9f7c-877602f9dd66}
CLSID|{e2ca7cd1-1ad9-f1c4-3d2a-dc1a33e7af9d}
CLSID|{e5ad5bd5-c710-45e0-abd3-e770fe85dae8}
CLSID|{ea26ce12-de64-a1c5-9a4f-fc1a64e6ac2e}
CLSID|{eb5ca3af-26c1-467b-9a55-2820e0451aab}
CLSID|{ee2975b6-e8d5-405e-8448-8fe9590f6cfb}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareQuake.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler , {E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}
DIREC|%programfiles%\spyquake2.com
DIREC|%ProgramFiles%\SpywareQuake.com\
DIREC|%ProgramFiles%\SpywareQuake\
DIREC|%userprofile%\Start Menu\Programs\SpyQuake2.com
DIREC|%USERPROFILE%\Start Menu\Programs\SpywareQuake\
DIREC|%Windir%\System32\1024\
DIREC|%Windir%\System\1024\
AUTST|bestreak
AUTST|SpyQuake2.com
AUTST|SpywareQuake
AUTST|SpywareQuake.com
RKSOF|SpyQuake2.com
RKSOF|SpywareQuake
RKSOF|spywarequake2.com
UINST|SpyQuake2.com
UINST|SpywareQuake
UINST|spywarequake2.com
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\SpyQuake2.com 2.3.lnk
FILEN|%AppData%\Microsoft\Internet Explorer\Quick Launch\SpywareQuake 2.0.lnk
FILEN|%userprofile%\Desktop\SpyQuake2.com.lnk
FILEN|%UserProfile%\Desktop\SpywareQuake.lnk
FILEN|%userprofile%\Start Menu\SpyQuake2.com 2.3.lnk
FILEN|%UserProfile%\Start Menu\SpywareQuake 2.0.lnk
FILEN|%WINDir%\system32\atmclk.exe
FILEN|%WINDir%\system32\dcomcfg.exe
FILEN|%Windir%\System32\dvdcap.dll
FILEN|%Windir%\System32\sivudro.dll
FILEN|%WinDir%\System32\stickrep.dll
FILEN|%Windir%\System32\suprox.dll
FILEN|%WINDir%\system32\xenadot.dll
SAFEM|QuakeSafeMode
FILEN|spy-quake2.exe
NEWPR|3572|SpyWare Secure
PRCAT|43
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Spyware-Secure
DIREC|%programfiles%\Spyware-Secure\
DIREC|%userprofile%\Start Menu\Programs\Spyware-Secure\
AUTST|Spyware-Secure
RKSOF|Spyware-Secure
FILEN|%temp%\NSIS_SpywareSecure_trial_setup.exe
FILEN|%userprofile%\Desktop\Spyware-Secure.lnk
FILEN|spyware-secure_trial.exe
FILEN|spywaresecure_trial_setup.exe
NEWPR|2850|Spyware Soft Stop
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\Spyware Soft Stop\
DIREC|%ProgramFiles%\Spyware Soft Stop\
AUTST|Software Soft Stop
AUTST|s_reg
UINST|Spyware Soft Stop_is1
NEWPR|2911|Spyware-Wiper
PRCAT|43
FILEN|slimshieldinstall.exe
NEWPR|3461|SpywareLocked
PRCAT|43
CLSID|{02743820-2e7c-42c6-b60c-726d67379edb}
CLSID|{07a582e8-bae3-457d-9d29-2048de45a369}
CLSID|{0b847a1a-a872-95fc-8e22-f8b4ae044657}
CLSID|{15a6894b-53b5-46c0-8c38-050e21ddd201}
CLSID|{17468406-36b6-4bd1-9b6c-3cc320cf28f6}
CLSID|{2f3ff99d-e078-4968-b9c1-87a74c7736cb}
CLSID|{34a0b812-915e-46f2-9f29-df0f0cf97611}
CLSID|{3d8286f5-9606-46c5-89d8-9b6379877732}
CLSID|{46018fd4-1675-4020-85dc-a3a0eeb7bda0}
CLSID|{521c4c7e-d2cf-4eb1-a078-6e126269e0ad}
CLSID|{5a74e275-351b-4072-8f0b-cbe2b7231b37}
CLSID|{655c070f-6724-45bc-bd5e-23609b6d4a3f}
CLSID|{67e054fa-0f1e-4af8-899b-0b52660d7043}
CLSID|{697c34c8-bbac-418c-999a-a5525f4ff8c3}
CLSID|{711c2540-aa7d-4c40-a8c0-9b1bc920378d}
CLSID|{78c9e0da-3bb5-4156-a03c-8326322f10dd}
CLSID|{7f21289a-bb27-49e9-92c3-2bf7910b6072}
CLSID|{80a2bfbd-7906-48ef-9f76-49b9f822393b}
CLSID|{87a8c087-37c2-40c4-9cdf-97437a9f54ba}
CLSID|{88c13519-616e-4a0d-b9ef-441d04891b6f}
CLSID|{8ed3825e-77a7-41d4-bdcb-fd8cc2b0d183}
CLSID|{94e13fca-4bac-4c2a-a5df-746460090f9e}
CLSID|{9d6fac42-a7be-4702-87ef-75d8dc14249e}
CLSID|{a0181cf2-4a15-4cb5-88d7-15eaa2d08a46}
CLSID|{a2e56d03-930a-4bbf-8c8e-4d63d15f88ee}
CLSID|{abae0daf-a6ba-481f-b3ba-0666d0d1b2eb}
CLSID|{b5b6aa2c-f0c7-44b9-a861-261958ecd0b8}
CLSID|{bd8c66a5-617b-4abf-b56d-f547597fe0fa}
CLSID|{cebea6db-dae7-4146-baba-1fbcd1d50426}
CLSID|{d152938d-32e1-43a6-81c7-898502aabf9a}
CLSID|{d675fd26-7200-466f-a380-182fe49af8aa}
CLSID|{d8073d3d-d957-45be-82ca-bb44fd0e9c4b}
CLSID|{dd348ac9-1d04-439a-b451-9a83bd66423b}
CLSID|{deb2fc31-ccc1-4d85-869f-d288e2386dbd}
CLSID|{ef906cf9-6eeb-4626-9a17-2e48c11d2995}
CLSID|{f9a34e6b-4c2a-4f58-b302-79caccd62c5a}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareLocked 3.5.exe
DIREC|%programfiles%\SpyLocked\
DIREC|%programfiles%\SpywareLocked 3.3\
DIREC|%programfiles%\SpywareLocked 3.5\
DIREC|%PROGRAMFILES%\SpywareLocked\
DIREC|%userprofile%\Start Menu\Programs\SpywareLocked 3.5\
AUTST|spywarelocked
AUTST|SpywareLocked 3.3
AUTST|SpywareLocked 3.5
RKSOF|SpywareLocked
RKSOF|SpywareLocked 3.5
UINST|SpywareLocked
UINST|SpywareLocked 3.5
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\SpywareLocked 3.5.lnk
FILEN|%userprofile%\Desktop\SpywareLocked 3.5.lnk
FILEN|%userprofile%\Desktop\SpywareLocked.lnk
FILEN|%userprofile%\Start Menu\SpywareLocked 3.2.lnk
FILEN|%userprofile%\Start Menu\SpywareLocked 3.5.lnk
FILEN|spywarelocked 3.5.exe
FILEN|spywarelocked.exe
NEWPR|2136|SpywareNo!
PRCAT|43
CLSID|{eee7178c-bbc3-4153-9dde-cd0e9ab1b5b6}
DIREC|%ProgramFiles%\Spysheriff\
DIREC|%ProgramFiles%\SpywareNo\
DIREC|%userprofile%\Start Menu\Programs\SpySheriff\
WINDO|SpySheriff Control Panel
AUTST|SNInstall
AUTST|SpySheriff
RKSOF|SNO2
RKSOF|SpySheriff
UINST|SpySheriff
FILEN|%userprofile%\desktop\spysheriff.lnk
FILEN|spysheriff.exe
NEWPR|2869|SpywareSheriff
PRCAT|43
CLSID|{202b0efd-2cb9-039b-2b11-a3579d6d56a3}
CLSID|{7c43e35c-a398-7c5f-b1ba-7e87073be150}
CLSID|{9cb4ce93-8cc7-9e03-1037-2dd837e3a52e}
CLSIA|{d8a8a7f1-53ef-41f2-b44d-f3e2e595dc27}
CLSID|{dfa61db1-388e-4c87-8d56-540fa229bcb4}
DIREC|%allusersprofile%\Start Menu\Programs\SpywareSheriff\
DIREC|%appdata%\SpywareSheriff\
DIREC|%ProgramFiles%\SpywareSheriff\
UINST|spy sheriff
UINST|SpywareSheriff_is1
NEWPR|2438|Spywarestrike
PRCAT|43
CLSID|{0f25878f-f8ae-5d5d-2bb7-31b5f803290d}
CLSID|{0f345791-d507-4f1c-9e44-8beec61d6148}
CLSID|{15462503-7597-4662-9c63-31c42112d4e9}
CLSID|{17412fea-fb37-4fc0-b689-dcf84fc7fb0a}
CLSID|{27150f81-0877-42e9-af13-55e5a3439a26}
CLSID|{2c15cdea-3ef4-4405-90b0-19a1389b36ed}
CLSID|{3115a433-3fa0-483b-ab01-2a61c951fe58}
CLSID|{4dc8dca1-191d-4bd9-bcfe-44df358ae036}
CLSID|{51fefa9c-1d5a-41c4-81fe-8c0fbe9254f0}
CLSID|{5b395871-7173-4b84-986a-a7112f1bdb45}
CLSID|{5ccc8d01-9f75-4f07-9acf-deb314176c79}
CLSID|{5e7bf614-960b-4a1f-9236-9ec01ac4c5e2}
CLSID|{66f0ac1c-ded5-4965-9e31-39788df1b264}
CLSID|{72daa86e-db4a-42b0-b82a-41a6de2b315e}
CLSID|{732eb0fc-c608-40b1-b524-b092e3915316}
CLSID|{849e056a-d67a-431e-9370-2275f26d39b5}
CLSID|{8504b09f-e628-4af9-8f8f-f2f73e4b46ab}
CLSID|{8b7afbfd-631c-45ba-9145-f059eb58dd73}
CLSID|{8d6083dc-ad33-44db-a8f1-b3b520af9891}
CLSID|{900fe140-70c1-4043-b32d-c89412399fb6}
CLSID|{95a5de55-9979-4507-a521-2e1f8bcc61ab}
CLSID|{a1c155d5-80a0-4bf2-ac7a-53b027c47879}
CLSID|{afeb8519-0b8b-4023-8c15-ffb17d5225f9}
CLSID|{b5775c39-bfef-4fa2-a194-550807a95146}
CLSID|{ba9cc151-4581-438e-94af-4c703201b7ca}
CLSID|{bc74c336-ff2c-40c9-ad4e-3772c208406b}
CLSID|{bdf00f24-a571-4392-95ec-04fdff82a82c}
CLSID|{c1a4c0c9-dbd0-493a-93f8-0b05edc96224}
CLSID|{c4e953e6-770e-4f59-a5e3-43e9f0d682e2}
CLSID|{ca8beb64-4a47-411b-87a1-488643df9521}
CLSID|{d0ab917d-1645-4eeb-b9bb-b33103845ed9}
CLSID|{e0105e7c-d0c4-4dea-aa21-b02f2960ecaf}
CLSID|{e809d2ae-7550-4540-bd5c-4e214ee86661}
CLSID|{ed39cb7c-1bf6-429b-a275-f183b4a3efcb}
CLSID|{ed9f5c8f-c607-4928-9d6c-47484e9a0fee}
CLSID|{f23aa637-31d5-4526-b5c6-9ff89e16202c}
DIREC|%programfiles%\Spyware Strike\
AUTST|SpywareStrike
FILEN|spywarestrike.exe
FILEN|ss_setup.exe
NEWPR|3530|StartGuard
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\StartGuard\
DIREC|%programfiles%\StartGuard\
DIREC|%windir%\SGQuarantine\
AUTST|StartGuard
RKSOF|StartGuard
UINST|StartGuard Free Edition_is1
FILEN|%userprofile%\D
esktop\StartGuard.lnk
FILEN|%windir%\SGPro.exe
FILEN|%windir%\SGPro.log
FILEN|sgpro.exe
FILEN|sg_free.exe
NEWPR|3049|SystemDoctor 2006
PRCAT|43
CLSIA|{09f1adac-76d8-4d0f-99a5-5c907dadb988}
DIREC|%allusersprofile%\Start Menu\Programs\SystemDoctor 2006 Unregistered Version
DIREC|%programfiles%\systemdoctor 2006 free
CLASS|SystemDoctor.Free
RKSOF|SystemDoctor 2006 Free
UINST|USDR6_is1
FILEN|%windir%\downloaded program files\usdr6_0001_d08m0404netinstaller.exe
IEZON|http://*.systemdoctor.com
IEZON|systemdoctor.com
FILEN|sd2006.exe
FILEN|systemdoctor2006freeinstall.exe
FILEN|systemdoctorfreesetup.exe
NEWPR|2607|SystemStable
PRCAT|43
DIREC|%allusersprofile%\Start Menu\Programs\SystemStable\
DIREC|%ProgramFiles%\SystemStable\
UINST|SystemStable_is1
NEWPR|2934|Titan Shield Antispyware
PRCAT|43
CLSID|{5e8fa924-def0-4e71-8a82-a11ca0c1413b}
NEWPR|2929|TrustCleaner
PRCAT|43
CLSID|{24e27ea9-fcf3-444f-bd80-20543ba5d946}
DIREC|%ProgramFiles%\Trust Cleaner\
DIREC|%userprofile%\Start Menu\Programs\Trust Cleaner\
AUTST|Trust Cleaner
RKSOF|Trust Cleaner
UINST|Trust Cleaner
UINST|Trust Cleaner Promo
FILEN|%userprofile%\Desktop\Trust Cleaner.lnk
SERVK|TrustCleanerDriver
NEWPR|3174|Ultimate Cleaner
PRCAT|43
DIREC|%ProgramFiles%\Ultimate Cleaner\
AUTST|Ultimate Cleaner
NEWPR|2904|Ultimate Defender
PRCAT|43
DIREC|%allusersprofile%\start menu\ultimate defender
DIREC|%appdata%\ultimate defender
DIREC|%programfiles%\ultimate defender
AUTST|a856cdb1.exe
AUTST|Ultimate Defender
RKSOF|ultimate defender
UINST|ultimate defender
FILEN|%userprofile%\desktop\ultimate defender.lnk
IEZON|flingstone.com
NEWPR|2813|UnSpyPC
PRCAT|43
CLSID|{bf69df00-4734-477f-8257-27cd04f88779}
DIREC|%ProgramFiles%\UnSpyPC\
DIREC|%userprofile%\Start Menu\Programs\UnSpyPC\
AUTST|UnSpyPC
RKSOF|UnSpyPC
UINST|UnSpyPC
FILEN|%userprofile%\Desktop\UnSpyPC Scanner & Monitor.lnk
NEWPR|514|Virtual Bouncer
PRCAT|43
CLSID|{0990e9a3-fc49-4aa8-91ce-f738bcbb7c8f}
CLSID|{13c243a0-50e9-43f4-8e5b-9ff857c3a0b5}
CLSID|{18bbdf4d-611d-41ce-a7e7-b2dd23c250d1}
CLSID|{25ae1a9b-87d2-418f-a3a6-5a46edc37a84}
CLSID|{261214cb-3021-4de0-9d21-5957acd1781a}
CLSID|{2c2ebd54-ed76-4343-902b-336d1db63763}
CLSID|{36c9c487-e14f-4bb9-9882-ac613193ee46}
CLSIA|{41f31718-2b9d-4f76-85e2-dd11bba99f8d}
CLSID|{4a277e1b-b130-4e4a-92ae-8712f4a150bd}
CLSID|{4b795337-d704-49c7-8ca1-d65722b28ebd}
CLSID|{6a4c71b1-1a79-483a-a400-f026936cc7b7}
CLSID|{6cdc3337-01f7-4a79-a4af-0b19303cc0be}
CLSID|{6d37ded8-1944-4e32-93fd-b9610e0ad8e3}
CLSID|{6e0ed53c-9908-49ed-b055-7cb31b162577}
CLSID|{73d7abfe-d325-430a-817f-64c7bfd48813}
CLSID|{795398d0-dc2f-4118-a69c-592273ba9c2b}
CLSID|{8551311d-f3bf-4718-ad66-96e302500735}
CLSID|{85d1e607-0c1a-4e69-ba9b-2e5ffa382d68}
CLSID|{88eb5b21-0fe7-4208-8f1c-26915f7e2432}
CLSID|{8940e505-72c6-44de-be85-1d746780efbf}
CLSID|{8c53bd8e-b12d-4c8f-ad0e-c9ddc39d1273}
CLSID|{8c7ab65b-830c-442a-a71a-0e06baf9caf2}
CLSID|{8dd9b882-0041-449d-a0bd-77a87119ad90}
CLSID|{92dd4b20-de93-4f74-8bca-ec7f88fdac5d}
CLSID|{934e4898-de90-45e1-adf4-c383dcae7b26}
CLSID|{950695da-8f77-4852-ad93-8c1e64995d4b}
CLSID|{9bcdd51b-4a7b-446c-8452-d32d38004582}
CLSID|{9cc6f6d3-8b13-4206-abc1-8b285f9413a7}
CLSID|{9fe4d9e6-13bb-43e0-8c74-9800573da4d6}
CLSID|{a85c505e-aae3-4cb0-aee1-cb8213b140fb}
CLSID|{a986f4db-792e-4571-8974-0bb6e024766f}
CLSID|{b0be4bbc-c1b6-4ea3-b346-7358fec20248}
CLSID|{be05f07d-131c-4935-941b-0d41ceb07e67}
CLSID|{be40278c-1c4e-4a63-bc3d-811646900a1a}
CLSID|{ce23505d-68fb-4c49-ae4b-d4f1cf86a2c4}
CLSID|{cf0fbbf5-1ddd-4d58-b480-ac2c2a4186d3}
CLSIA|{d9ec0a76-03bf-11d4-a509-0090270f86e3}
CLSID|{db90dea9-0897-4b02-9fe0-1e321a22eab0}
CLSID|{db92433d-1902-4789-bafc-b46b0dcdebb7}
CLSID|{dcb5773b-4d84-4e6f-8e21-96f2a5b431a8}
CLSID|{e2b951f0-9f32-4260-90f7-a988beff7f0c}
CLSID|{ec352548-52b5-41ac-b8c1-8cb561ecf7ad}
CLSID|{eec056ce-3e1b-4571-bee1-eab9876b35f8}
CLSID|{f3a1bec7-6d42-4a5d-abdc-534669a087e1}
CLSID|{f634e01a-833a-49fb-bae2-3a00cecc3a94}
REGKE|HKEY_CURRENT_USER\Software\VB and VBA Program Settings\VBouncer
DIREC|%allusersprofile%\application data\VBouncer
DIREC|%APPDATA%\vbouncer
DIREC|%programfiles%\bouncer
DIREC|%ProgramFiles%\Bouncer\
DIREC|%programfiles%\VBouncer
DIREC|%userprofile%\start menu\programs\Virtual Bouncer
AUTST|Bouncer RunStartup
AUTST|VBouncer
AUTST|VBundleOuterDL
AUTST|vcmxin
CLASS|VBDNR.cCookie
CLASS|VBDNR.cErrorLog
CLASS|VBDNR.cHistory
CLASS|VBDNR.cRegistryRoutines
CLASS|VBDNR.cScheduler
CLASS|VBDNR.cSignature
CLASS|VBDNR.cThreatLevel
CLASS|VBDNR.cUserSettings
CLASS|VBDNR.DNRDirector
RKSOF|VBouncer
UINST|Virtual Bouncer
FILEN|bundleouter2601031121.exe
FILEN|swrt01.dll
FILEN|vb2uninstaller4_19.exe
FILEN|vbdnr.dll
FILEN|vbouncerinner.exe
FILEN|vbouncerinner1007.exe
FILEN|vbouncerinner1106.exe
FILEN|vbouncerinner1107.exe
FILEN|vbouncerinner1108.exe
FILEN|vbouncerinner1109.exe
FILEN|vbouncerouter1123030429.exe
FILEN|vbouncerouter1203.exe
FILEN|virtualbouncer.exe
FILEN|virtual_bouncer.exe
NEWPR|3058|VirusBlast
PRCAT|43
CLSID|{0d0fab5c-2be4-4126-a28e-828febce1e55}
CLSID|{1131081d-81ed-46f0-8b03-b728aeaffd12}
CLSID|{1f6fe2c2-6040-4645-9053-7f689affe176}
CLSID|{214345b8-bb69-498d-a168-29f58f15d806}
CLSID|{283ed043-d403-4808-bf28-fcde29dcf1fb}
CLSID|{490e7d57-1fc1-4ea6-bd52-483b7271b223}
CLSID|{6994ad04-93ef-11d0-a3cc-00a0c9223196}
CLSID|{80ed1eb2-55fb-4434-bd41-e1645a370158}
CLSID|{9da04bbd-71bb-020c-436e-42fecbb98f05}
CLSID|{9da1990b-9bca-4c80-aefb-11a40fa849f9}
CLSID|{e6b4ab50-f423-4ee6-9839-b35dcfcdfa49}
DIREC|%programfiles%\virusblast\
AUTST|VirusBlast
RKSOF|VirusBlast
UINST|VirusBlast
NEWPR|3299|VirusBurst
PRCAT|43
CLSID|{0249beb1-a2aa-45a3-9ec5-95d9c4a40a62}
CLSID|{02a40ea7-b5b4-4f41-b2ff-2a8a0aec50cf}
CLSID|{082da6af-f994-4c6c-a2b0-dfc3b3ff540a}
CLSID|{0c25003b-f5c9-4c24-a5f8-5bee543a562c}
CLSID|{0c9a71b1-8a8a-48a1-aa3f-0c83ce1c0bbd}
CLSID|{0ef25077-da22-4ff2-b6ff-6fc1c26f5740}
CLSID|{150d28ac-7c2d-4b57-b837-c74dce7cc728}
CLSID|{20dc1f8e-4640-4fff-9858-05e7b978cc71}
CLSID|{2613cf74-4fc5-4251-9f48-260496364852}
CLSID|{276d86b8-010b-4576-8444-9a670070a3f4}
CLSID|{27d8cd06-82e3-4e1e-8917-86a9b3ae41f6}
CLSID|{2d9caf75-4b36-455b-adef-0cfd7adf3154}
CLSID|{38cd62aa-98ac-4b47-9cb8-8e1f108ad32f}
CLSID|{3b021ad8-9999-4efe-8203-36a5b09117d7}
CLSID|{3c975d06-9239-4a00-9f1a-c3c337912f22}
CLSID|{413d2fa5-98cd-4078-98c1-c3ae775ef050}
CLSID|{41f834da-af4b-4c04-bd2e-9fa131ff39e5}
CLSID|{46722628-c282-4fdf-814d-5b819c78e067}
CLSID|{48ce44bf-e439-46de-8cd8-88cb5b3d6d6e}
CLSID|{49a6d89f-4422-4474-a287-5fe1d6811a87}
CLSID|{4d993022-0899-4599-b4b6-0f887d0802e6}
CLSID|{4f7fa7bf-007c-46e6-a49c-b8e7373c046e}
CLSID|{4fc003c3-87a0-489c-85cd-878246eb2d18}
CLSID|{5f412259-081e-4b21-815d-93ae1e71ae95}
CLSID|{66b01f8a-1d57-40e7-8c8d-d67d06662577}
CLSID|{6a66cc28-f0a2-fcbc-d3d5-1ea3001ed26a}
CLSID|{7588c5e3-9c6e-4cfe-884f-71bf8383621a}
CLSID|{78ea0c93-1aaa-4922-84f0-42cba685f6bc}
CLSID|{7caefbcd-55a9-4a68-aa02-e69b12b3be57}
CLSID|{8122d5a8-dc59-4ab8-9c02-cf66e10641c2}
CLSID|{887d7071-fb68-49f6-a77c-e12d0a83bf91}
CLSID|{898272cf-3ace-4a7b-98fa-9eb8db8b26dc}
CLSID|{8cbf5bac-e609-4863-abc9-68a7bd13b1d0}
CLSID|{8fb11528-3a97-45fe-beaa-1a1fc4ee45f5}
CLSID|{8fe88dc0-e1ec-43e3-b70e-d3246f4d1899}
CLSID|{9981ddef-81c4-4cc8-a5f2-62a7912d8037}
CLSID|{9cb68df7-f336-45a2-bde2-5dca3998986f}
CLSID|{9ecef347-16e8-45b3-bb6d-ae9ddfc4ec11}
CLSID|{9ee20753-220c-4a2c-87dc-f86fb78f3774}
CLSID|{a25f0022-c2fc-4ea0-abba-2bfe4635bd68}
CLSID|{a4bb2045-c8b4-4a9f-b509-7a626797b961}
CLSID|{a537df83-75f0-e83c-5665-e5e8f23f996e}
CLSID|{b4bb620f-3ae7-4910-8171-f9fc8120d9ef}
CLSID|{bdc75ad7-a8a5-4f25-be36-a4db971c7541}
CLSID|{bed38b7d-66e0-47b2-a7ef-8682b62828d6}
CLSID|{c49930c7-abf8-43b4-a7b7-98013dd6abe6}
CLSID|{c97c3b7c-e022-4fa8-b1a7-1c28270ffaff}
CLSID|{d838d7a3-1551-4b32-bf7a-7f4f769bb885}
CLSID|{d87a739b-ad9a-4973-b8c5-9d55b3ec0401}
CLSID|{e1751f23-00e6-4f6c-ad78-ca7d8a96fd3e}
CLSID|{ec6921c1-f723-49c9-b760-274de8238ed6}
CLSID|{eca9fbff-5415-4440-a92b-03e8ca7b9828}
CLSID|{ed639b1f-1b3f-473f-bd8d-6de9c2d1972a}
CLSID|{f31aee4a-1530-4fef-8537-79c6973bff9a}
CLSID|{f7996a4a-b172-4c1a-85d0-19ab61c9c512}
CLSID|{f83e8f99-ae49-45d6-92b4-59854bf0a759}
CLSID|{fbea0445-4c4a-4136-864a-c72a4a182a84}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\virus-bursters.exe\
DIREC|%programfiles%\Virus-Bursters\
DIREC|%USERPROFILE%\Start Menu\Programs\Virus-Bursters\
WINDO|Virus-Bursters 6.3
AUTST|Virus-Bursters
RKSOF|Virus-Bursters
UINST|Virus-Bursters
FILEN|%APPDATA%\Microsoft\Internet Explorer\Quick Launch\Virus-Bursters 6.3.lnk
FILEN|%USERPROFILE%\Desktop\Virus-Bursters.lnk
FILEN|%userprofile%\Start Menu\Virus-Bursters 6.3.lnk
FILEN|vb_distrib.exe
FILEN|virus-bursters.exe
NEWPR|3699|VirusProtectPro
PRCAT|43
CLSID|{049fece3-18c7-4023-a1be-cfaa2c4ee387}
CLSID|{07420914-e5a0-451e-bfd4-aa1b799d39ad}
CLSID|{0b6c7539-c6d5-4dde-9632-184f421ef8d7}
CLSID|{164913b3-fcde-45b5-8901-1750f4e3119e}
CLSID|{1d52bb09-465c-4aa4-9fbd-71d1690caed3}
CLSID|{24998748-6e8a-40d1-aa97-e9952ee9ed18}
CLSID|{287ffe0c-15d0-4bfd-baa9-0582c6361bbb}
CLSID|{365036eb-87c2-4627-8fbc-ef6e9e
8da5c2}
CLSID|{45973d31-5ce3-4503-bc81-25e525119c48}
CLSID|{45c2fdbe-1d46-b98e-f9a9-9d44b93a9d52}
CLSID|{46d4d563-1c43-4cee-af98-471385f2bc42}
CLSID|{5596a310-2e54-4b75-ada3-7ee0ad10e228}
CLSID|{5c17f7d3-8460-4488-84eb-986a38bedd2d}
CLSID|{64d6666f-b95e-4048-9fa5-f68b094ea030}
CLSID|{69b73aa0-ca0c-4be6-9811-eb0d951b5b99}
CLSID|{6d88033c-6fd8-4374-9532-7ea301df08ae}
CLSID|{71df187c-dc99-4a35-bdb2-c099821a435d}
CLSID|{74df3f5e-99d7-4f4d-81c3-95201d4cda88}
CLSID|{77345588-ab75-4cda-873f-aae78c01efcd}
CLSID|{91478017-ff82-4c5d-9fff-7801f8d99ccc}
CLSID|{9af8f31b-b778-4413-b8ed-ae63a62e1f7d}
CLSID|{9f9c8cf3-eb4a-4851-a4f6-2370f5bc79ee}
CLSID|{b1b9c911-ca24-4e1e-9f56-838486218327}
CLSID|{b56ed873-c3d3-4202-9ef8-fb31dee2c207}
CLSID|{bb3ebaf2-f4c4-4b66-9a98-eed3b70d1bb3}
CLSID|{c5cc0894-ad1e-47ad-9265-0f463ae30508}
CLSID|{c7604d71-cd16-4976-9383-d24b6fad052e}
CLSID|{c78e49c0-ab82-4c79-a189-f1e34980643b}
CLSID|{d2a0598f-fbc4-4721-bc85-f75c0712c100}
CLSID|{d42cf3bb-e79e-4c0b-b434-6841ca9c4593}
CLSID|{d8c36036-2e41-4ce0-9351-99087dd28a29}
CLSID|{e60a0f09-dd6b-4343-84b0-c33b946d5a9c}
CLSID|{e6369bca-e4fa-4497-89c5-ecf9268b64b1}
CLSID|{e7b2831e-a25a-430b-b3e3-3d414f9c4288}
CLSID|{edc652ff-2ea2-4e46-8849-d9041b77b88e}
CLSID|{f040e242-bad6-46f7-a787-d3ab811e5bc3}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\VirusProtectPro 3.4.exe 3.4
DIREC|%programfiles%\VirusProtectPro 3.4\
DIREC|%userprofile%\Start Menu\Programs\VirusProtectPro 3.4\
AUTST|VirusProtectPro 3.3
AUTST|VirusProtectPro 3.4
RKSOF|VirusProtectPro 3.4
UINST|VirusProtectPro 3.4
FILEN|%appdata%\Microsoft\Internet Explorer\Quick Launch\VirusProtectPro 3.4.ln
FILEN|%userprofile%\Desktop\VirusProtectPro 3.4.lnk
FILEN|%userprofile%\Start Menu\VirusProtectPro 3.4.lnk
FILEN|VirusProtectPro 3.4.exe
NEWPR|1818|Wareout
PRCAT|43
DIREC|%appdata%\Start Menu\Programs\WareOut
DIREC|%ProgramFiles%\WareOut
AUTST|backorif
AUTST|bingo9
AUTST|ERTYDF
AUTST|ExchangeMaster
AUTST|EXE32EXE
AUTST|ftbar
AUTST|hclean32.exe
AUTST|JAguAr
AUTST|jopplerg
AUTST|newbreed
AUTST|NsCplTray
AUTST|ParisM
AUTST|TemplateDongle
AUTST|Trayz
AUTST|uio
AUTST|UserSp1
AUTST|WareOut
AUTST|WhatsNewBot
RKSOF|WareOut
UINST|WareOut
FILEN|%appdata%\Desktop\WareOut Scanner & Monitor.lnk
FILEN|wareoutupdate.exe
NEWPR|2741|WinAntiSpyware
PRCAT|43
CLSID|{2b798a44-7dfc-4c46-bd8f-41259d169a0d}
CLSID|{328ba26a-1619-47ee-a37d-7d7a6ab1b000}
CLSID|{4d05a335-1a1c-46b3-bcff-7f25b326895c}
CLSID|{8576de55-eded-4675-af10-ba15eddb4d7a}
CLSID|{d4c0649b-b980-44a5-b259-9b09ebea6331}
CLSID|{e69f0d6a-1c69-4a04-8709-5eac2019d9be}
CLSID|{fc0b8eb8-ae24-4fd6-b479-e2b464f32da6}
DIREC|%allusersprofile%\Start Menu\Programs\WinAntiSpyware 2005\
DIREC|%ProgramFiles%\Common Files\WinSoftware\
DIREC|%ProgramFiles%\WinAntiSpyware 2005\
AUTST|WinAntiSpyware 2005
RKSOF|WinSoftware\WinAntiSpyware 2005\
FILEN|%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinAntiSpyware 2005.lnk
FILEN|%userprofile%\Desktop\WinAntiSpyware 2005.lnk
NEWPR|2731|WinAntiVirus
PRCAT|43
CLSID|{025c9956-0606-4583-bc40-633904ff6d77}
CLSID|{11d14da6-fcaa-405e-b014-e5920f922ac1}
CLSID|{1bd800a1-1c40-47e6-99a1-22b04dab2ce0}
CLSID|{2178f3fb-2560-458f-bdee-631e2fe0dfe4}
CLSID|{26ea10bd-85b6-4052-9300-59aac07e84ef}
CLSID|{3f9d0c61-737d-44d1-bd80-91af857061cc}
CLSID|{406b7088-1e9d-48c4-b7b2-4ff9738997ab}
CLSID|{4e34ab3c-05d2-438e-a408-06cb9467038d}
CLSID|{5d65f8b9-6c63-4227-ab90-04e8d2b87c31}
CLSID|{5f4c4961-505d-4da5-b770-bf3d860c0207}
CLSID|{62b74dc2-2c6f-4dae-9e39-fffb8018c47b}
CLSID|{66ba5dc6-bba9-470f-a68d-37ccd9ab6788}
CLSID|{82b9a1fb-6b6b-47d2-8ced-b9a494f26f48}
CLSID|{8aa798d6-fa74-43d3-8121-321b21cb9c3b}
CLSID|{8acf7e80-3254-4f9a-9d11-39e10e04973a}
CLSID|{989adb33-3ee9-4a36-8113-76d1b79b606b}
CLSID|{b5141620-c2b2-4d95-9f0f-134d99c87ab0}
CLSIA|{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a}
CLSID|{bad54733-5051-485e-b8f0-8a78bebd80fc}
CLSID|{c0a3779c-3345-4150-bd63-c399eb32661e}
CLSID|{feb5c757-2f1d-4939-a069-42564648403b}
DIREC|
%ProgramFiles%\Common Files\WinAntiVirus pro 2006\
DIREC|%allusersprofile%\Application Data\WinAntiVirus Pro 2007\
DIREC|%allusersprofile%\Application Data\WinSoftware\WinAntiVirus 2005\
DIREC|%allusersprofile%\Start Menu\Programs\WinAntiVirus 2005 Trial\
DIREC|%allusersprofile%\Start Menu\Programs\WinAntiVirus 2005\
DIREC|%allusersprofile%\Start Menu\Programs\WinAntiVirus Pro 2007\
DIREC|%ProgramFiles%\Common Files\WinAntiVirus 2005 Trial\
DIREC|%ProgramFiles%\Common Files\WinAntiVirus 2005\
DIREC|%ProgramFiles%\Common Files\WinAntiVirus Pro 2007\
DIREC|%ProgramFiles%\WinAntiVirus 2005 Trial\
DIREC|%ProgramFiles%\WinAntiVirus 2005\
DIREC|%programfiles%\WinAntiVirus Pro 2006\
DIREC|%ProgramFiles%\WinAntiVirus Pro 2007\
DIREC|%userprofile%\Application Data\SystemDoctor 2006 Free\
DIREC|%userprofile%\Application Data\WinSoftware\WinAntiVirus 2005\
AUTST|%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinAntiVirus 2005.lnk
AUTST|%userprofile%\Desktop\WinAntiVirus Pro 2007.lnk
AUTST|DNSE
AUTST|fat.exe
AUTST|mav_startupmon
AUTST|Nls
AUTST|rtasks
AUTST|runner1
AUTST|uwa6pcw
AUTST|uwa7pcw
AUTST|WinAntiVirus Pro 2007
AUTST|winantivirus.com
AUTST|WinAntiVirusPro 2007
AUTST|WinAntiVirusPro2006
CLASS|AntiVirusCOM.AVOfficeProtect
CLASS|IEFWBHO.IEFW
RKSOF|WinAntiVirus Pro 2007
RKSOF|winsoftware\winantivirus 2005
RKSOF|winsoftware\winantivirus 2005 trial
FILEN|%Allusersprofile%\Desktop\WinAntiVirus Pro 2006.lnk
FILEN|%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinAntiVirus 2005 Trial.lnk
FILEN|%userprofile%\desktop\remove spyware.url
FILEN|%userprofile%\Desktop\WinAntiVirus 2005 Trial.lnk
FILEN|%userprofile%\Desktop\WinAntiVirus 2005.lnk
SERVI|FWSvc
IEZON| http://www.winantivirus.com
IEZON| http://www.winantiviruspro.com
FILEN|winantiviruspro2006freeinstall.cab
NEWPR|2263|WinFixer
PRCAT|43
CLSID|{08c71fb1-1e66-4d22-9f32-4c045a451306}
CLSID|{0e9f6ac0-a21a-4591-910f-e2c6f3ca094c}
CLSID|{1cdeb41b-905a-4183-aa20-26e075419b46}
CLSID|{1ce1c25b-f8b4-4974-99d2-5d4ae96b9900}
CLSID|{25a3c995-10c8-474b-a167-99460ab4ab2b}
CLSID|{287a2bad-6590-4eff-9bbc-494385664a73}
CLSID|{290b5b73-4963-4ba1-9d2d-07cb566cb7fa}
CLSID|{30ed49a5-ca6c-4918-b5f3-5e6818c91d8b}
CLSID|{3496d13a-609a-407b-b181-8f47b4f28ae9}
CLSID|{35096c29-3507-4abe-b6d8-c7cc881be020}
CLSID|{38edb9e2-d7c4-4575-8905-fe65414ffead}
CLSID|{38f743a2-210f-49de-9b79-dcd501ced284}
CLSID|{3eec290d-fc13-4c83-803d-4802651eeb61}
CLSID|{41a5bbf6-3c9d-4cf9-9a99-32dd37cc290b}
CLSID|{48349992-1402-4c67-b45b-2e619e641fdb}
CLSID|{4dceea42-794d-4855-9ecc-20dcf5f4fea7}
CLSID|{4e4f38d9-8736-41ae-b192-e829ae194398}
CLSID|{4f79d1c5-24f9-4e59-8022-604d4b41d5ca}
CLSID|{538bc8f3-2e1e-4d2d-a261-158df6e9b407}
CLSID|{66484903-09f4-4330-927d-1f6c214221ac}
CLSID|{6a077841-5016-42c8-92c8-f2d6b865bcd1}
CLSID|{6dd0bc06-4719-4ba3-bebc-fbae6a448152}
CLSID|{7fa14ad6-d8e5-465f-9bd1-a37e26c1a74f}
CLSID|{8c65aef6-e413-4314-815b-82717a3f1603}
CLSID|{9e984934-cd94-4763-9dbc-618e483d4b7f}
CLSID|{ad70ac89-f460-4e7e-b5a5-7eaf7e207736}
CLSID|{b115bd8e-b008-46f4-b8b6-3405eb325c3c}
CLSID|{b5e427f9-ab38-4348-9076-86870c2be860}
CLSID|{b6625280-8cd8-4632-97c0-83cec12a49a3}
CLSID|{b9dfcf32-b679-4cad-b7fc-518a48ce3922}
CLSID|{cae8a9b1-abbd-4159-a485-1da045a5d4a1}
CLSID|{cbeef194-ebc5-4758-9b51-ac34fc135e70}
CLSID|{cd3604cc-2b95-43ee-afc9-e7444c21be1c}
CLSID|{ce70731d-f28d-4d81-9d61-c8ee60378401}
CLSID|{d21040fe-0a57-4fab-8ed2-f0e653e55809}
CLSID|{d7a2488e-53e4-4edd-aeaa-f24778beb100}
CLSID|{d7a6df8d-b6cf-4c27-8e99-eca2ce370ea7}
CLSID|{e8928e69-c050-42a9-8884-94de85e888a2}
CLSID|{f41c1430-cfde-4ad3-b38d-7890f0843e47}
CLSID|{f458adae-d53b-4859-b99f-9fa127791278}
CLSID|{f6c1582e-b11c-4724-b8f6-240457ef1d2a}
CLSIA|{f919fbd3-a96b-4679-af26-f551439bb5fd}
CLSID|{fb787d5e-0c7c-4bab-b45d-20325fb886db}
CLSID|{fc76a5b8-db35-4f3e-8b9a-bf0eea098d64}
DIREC|%allusersprofile%\start menu\programs\winfixer 2005\
DIREC|%commonprogramfiles%\winsoftware\
DIREC|%programfiles%\winfixer 2005\
DIREC|%programfiles%\winfixer2005\
AUTST|NI.UWFX5
AUTST|NI.UWFX5_0001_LP1014
AUTST|NI.UWFX5_0001_NI53TEST
AUTST|WinFixer 2005
AUTST|WinFixer2005
CLASS|compcleancore.appcleaner
CLASS|compcleancore.filecleaner
CLASS|df_fixer.Fix
CLASS|df_fixer.fixer
CLASS|ffcom.flfixer
CLASS|ffwraper.ffenginwraper
CLASS|fixcore.mmfixcore
CLASS|FlFxr.FlFixer
CLASS|MMFx.CoFixEngin
CLASS|UWFXPCheck.UWFXPCheck
RKSOF|winfixer
RKSOF|WinFixer2005
RKSOF|WinFixer_2005
RKSOF|WinSoftware
UINST|UWFX5_is1
UINST|WFX5_is1
FILEN|%ALLUSERSPROFILE%\Start Menu\Programs\WinFixer 2005\WinFixer 2005.lnk
FILEN|%USERPROFILE%\desktop\WinFixer 2005.lnk
FILEN|%USERPROFILE%\desktop\WinFixerScannerInstall.exe
IEZON|.winfixer.com
FILEN|compcln.dll
FILEN|df_fixer.dll
FILEN|df_proxy.dll
FILEN|ffwraper.dll
FILEN|fixcore.dll
FILEN|mmfix.dll
FILEN|wfx5.exe
FILEN|winfixer2005trialsetup.exe
NEWPR|2796|Winhound Spyware Remover
PRCAT|43
CLSID|{0878f045-b52e-46b3-9724-d3ae69d50067}
CLSID|{0baca3c1-f734-4a5f-970a-15dbf7d3c09c}
CLSID|{0d4385df-f78a-4264-a32c-7dd4a72de539}
CLSID|{0ea04
667-e53b-4e81-8e7c-de2ca114cbd6}
CLSID|{19a0b5c9-65fe-4d3b-8bdd-efb7fe553c58}
CLSID|{19c99256-d011-47e2-bc64-6322096e20a5}
CLSID|{265c2af8-c94c-4aff-b2b6-340d3982562c}
CLSID|{2871b7af-2d4c-478f-be89-881881c272ab}
CLSID|{2b94cdfd-4a45-4b08-b105-54c709d07b28}
CLSID|{2c354a9b-a5df-41a3-bf40-2d72feac14d3}
CLSID|{2c797aa0-978c-4ac2-bbb4-f89d410b614e}
CLSID|{31e956bf-8ca9-4d75-b534-7ebc79770002}
CLSID|{3946a33d-bbc6-4792-a383-d855e0f76d91}
CLSID|{41d7bb0a-64e0-4ab2-bd0b-69ea78e462e8}
CLSID|{4aa55e8c-2c19-4f3a-91ec-43b6df937c4f}
CLSID|{4f93062d-7bda-48be-aeb6-88af2b1fe2d4}
CLSID|{5206df89-97fc-41ad-bae3-993e87053a99}
CLSID|{54007809-0689-4a40-9d8f-94c79d87d931}
CLSID|{557c3787-d066-496e-8caf-ba47da7365c1}
CLSID|{58e68548-42e2-479d-a9e0-86d9f2eaf02e}
CLSID|{5c083b7e-a083-4b20-a7ad-7c8e29085494}
CLSID|{5e5a79a6-c67b-444e-be58-bd0acefcda07}
CLSID|{649d371e-d3e3-4fc0-ac82-e91f73d8e79e}
CLSID|{655980f1-13d5-4da2-9e80-aa56c36876cb}
CLSID|{67196b3e-55a0-49de-ba11-66f07df804db}
CLSID|{6af126a9-b07a-4de4-883e-28d3eccd75d8}
CLSID|{6b436bdd-8b8b-4a1f-add5-e67b30c8f7dd}
CLSID|{6e9e448e-b195-4627-953c-5377fa9bba36}
CLSID|{7198f8da-012c-4db4-abd8-923a54c87900}
CLSID|{71bf80fd-7e91-4730-b6e8-8f3e81f5c38b}
CLSID|{81723c8c-918f-4456-b7e8-a68cf7a10c6d}
CLSID|{82847700-fe61-46a3-b3ee-761a1e312aca}
CLSID|{82a10659-a1e5-4732-a839-c910d955c88b}
CLSID|{84844b27-0d53-4c71-ab24-0151b33ab02f}
CLSID|{8c2a05c5-780f-4a2e-ae1c-fb8181f860e4}
CLSID|{8dca6b3d-1fca-4500-b210-76119bb5c69e}
CLSID|{a8bcf2b9-ed19-4637-ac77-bf59f131fa1f}
CLSID|{a9a73a66-b0e0-4ffb-828f-3a55e1fa4271}
CLSID|{acc647ee-991a-4811-b420-f063f50cddc1}
CLSID|{b6049d5d-718f-44c0-b965-06840d27e206}
CLSID|{b817d284-1b82-4793-b1f3-58a06dab03a1}
CLSID|{bc077dd0-42b5-451c-b78c-4ac97e4b116b}
CLSID|{c123dba0-52df-4272-bbaa-bfd092d07c2e}
CLSID|{c5b70256-5b08-4056-b84e-c6ce084967f5}
CLSID|{cb9dd914-68b6-4710-a04e-4745470706ce}
CLSID|{cbe4b748-08f9-44db-8fb1-9ad25979da35}
CLSID|{cdd964c2-fb78-4a74-bb1e-1cb1fcb72018}
CLSID|{d25f7446-4d36-4203-9ea5-5422b26fa9d0}
CLSID|{de1e317f-716a-4784-ba90-fda6d6a8fad5}
CLSID|{e12aaacf-8af2-4c31-ba94-e3787b44f90e}
CLSID|{e36dcdbc-57ad-4a1c-b9c6-1161441b51ca}
CLSID|{e479197f-49e5-4e60-9fa2-a71d4c7c2bbc}
CLSID|{e51ac62c-e82e-4e60-97ab-c66c4969af39}
CLSID|{ef5750b1-0aba-45c5-bf12-fb4d1d1150d2}
CLSID|{f1d9585e-20a6-4689-84c7-c19fe21c9a71}
CLSID|{f1e1a6b0-6cac-471b-99c4-4dbada883be8}
CLSID|{f880b4f2-75bf-44ec-b7aa-45ec37448027}
CLSID|{f8c9d1a9-b7b7-47ca-8b93-27c5b64d3a47}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\WinHound spyware remover
DIREC|%allusersprofile%\Start Menu\Programs\WinHound spyware remover\
DIREC|%programfiles%\WinHound\
DIREC|%userprofile%\Start Menu\Programs\WinHound spyware\
AUTST|WinHound
UINST|WinHound spyware remover
FILEN|%ALLUSERSPROFILE%\Desktop\WinHound spyware remover.lnk
FILEN|%ALLUSERSPROFILE%\Start Menu\Programs\WinHound spyware remover\Register WinHound spyware remover.lnk
FILEN|%userprofile%\Application Data\Microsoft\Internet Explorer\Quick Launch\WinHound spyware remover.lnk
FILEN|%userprofile%\Desktop\WinHound spyware
FILEN|%userprofile%\Desktop\WinHound spyware remover
FILEN|%userprofile%\Desktop\WinHoundinstaller.exe
FILEN|%windir%\WinHoundInstaller.exe
FILEN|cwrapper.dll
FILEN|winhound.exe
NEWPR|2275|World Anti-Spy
PRCAT|43
DIREC|%AllUsersProfile%\Start Menu\Programs\WorldAntiSpy\
DIREC|%appdata%\skinux\worldantispy
DIREC|%programfiles%\worldantispy
RKSOF|WorldAntiSpy.com
UINST|WorldAntiSpy.com_is1
FILEN|worldantispy.exe
NEWPR|2599|X-Con Spyware Destroyer
PRCAT|43
DIREC|%programfiles%\X-Con Spyware Destroyer\
DIREC|%userprofile%\Start Menu\Programs\X-Con Spyware Destroyer\
UINST|X-Con Spyware Destroyer Beta 3.1.2
FILEN|%userprofile%\Desktop\X-Con Spyware Destroyer.lnk
NEWPR|2632|John The Ripper
PRCAT|44
NEWPR|3631|Pinch
PRCAT|44
FILEN|evcztdq_pinch.exe
FILEN|qmtsfzh_pinch.exe
]Nu1
ESPS
#t53
XJJJ
WD-b
M`XZ
WD-b
E3P3
|kernel32.dll
D$$%
8MZu
+K +
kernel32.dll
GetProcAddress
GetModuleHandleA
LoadLibraryA
user32.dll
advapi32.dll
oleaut32.dll
advapi32.dll
version.dll
gdi32.dll
user32.dll
oleaut32.dll
ole32.dll
oleaut32.dll
comctl32.dll
shell32.dll
wininet.dll
advapi32.dll
oleaut32.dll
GetKeyboardType
RegQueryValueExA
SysFreeString
RegSetValueExA
VerQueryValueA
UnrealizeObject
CreateWindowExA
SafeArrayPtrOfIndex
CoUninitialize
GetErrorInfo
ImageList_SetIconSize
ShellExecuteA
InternetSetOptionA
QueryServiceStatus
VariantChangeTypeEx
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
type="win32"
name="DelphiApplication"
version="1.0.0.0"
processorArchitecture="*"/>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
publicKeyToken="6595b64144ccf1df"
language="*"
processorArchitecture="*"/>
</dependentAssembly>
</dependency>
</assembly>
BWWb
RUrr
eXvvw
vE]]
E[[a
0UqqU
in5gX
Dr@9<
G4#0
$r 9`
CYT8
zX:;
jZ]_
w^$>u
@Dqe
UKSw
+dWS
G@IB
X,J|
!wtP
;R/?
t+b
E{&f
HK]0
$t ?
Y#m}
xla~{
a]Ri
LH+`
=DH$u,q
bm"p
5J<i
VF!H
Db(t
PRQ@.
#10t
A%R8
5hApb
-sZ
.#l8z
0lPj
YR@'
B) 90
SOFTW
\Borla>nd
FPUM
askV
`YPZR(
o0|_
?.Q[
ZTUW
@)10
,t\T
a/P(
0Kz&#
J;BWI
i:dhH
K|3D,5
ExH^
8 t>
7ubf
Porti
s COpy~
1983
Pa#EA
A~^*p
ThzB
Zs)i
0-Rf;
#;0c\
"XJ$
a8]@\(:
m.nB
PbV3
5q"#
f@8&
~ u&0
'|cp
%=z_
aOCM
xa/F?
\qfWcHy
9j[,/f`
/`A
RSu9
oftw
!WpA
%yB
?=%{
y0[!Hu
PE6^
2GZv
fRqK
Q(_*
XuIL$
TQ0Y
U@:?
BkU'
{@?v
)#VZ
-;,+#
^OA
q,/b<
<@N)
cD3
Vq-#
`nj4[xz
p?'u
CM`0
@|H<1
(r$9
-Pz_
GHIJK
OPQRST8UV
WXYZabcpd
efghijkl
nopqrst
wxyz01
5678
+/=
$()[
]{},;
\*"'
O?L%
g%IU
~n9v
R.f'u
$'x:
aWp[
mory
\qX8!
ternalA
9X^:
-,#lb
!lq\
EDivByZ
RangCe+
(`Pto
,BPrh
tack
DpHtk;lr
BN`@
2lS`
V~MD
\:@`
&6{A
;?(Q
^_qQ
q[c%`@4
L+<&
'R@%
r@<9
w7k{
&/<`R
&2nh`
K{c@
b-U@4
C`Y*X
AP"@
8fn<
6|H@
s'tz
C'<w~
np-w
AHSv
,PI2
zt{!?=
moswL
y*Os
<&j~
S0P*h
A\9@
.)s$
e0?@Yt
j$<DR
HpF
5Vj)
J7.Pj
(CBpw
H@GB
SpQy0Jz
FS#U
0GfI
IWEd
hZJ 9
8Jxy
f=)@
z`q,
*z~@
"(O4/
K6fC
J?!#
m/d)[q
AMP\)
@`l32.d
skFr
)pH_
#~(t
g4$|V
8zx@Pt
I9NF:A^\
QS]$f
.[Y9
$*@t
Li8^A
=Jti
<8't
D.51v9::;e
Y~mb`}e.
a)=D
Q1b0
J?,$
3n-
1Kc"
qm<p$
x>0U
5ES:
|vCj
BI<d
Mu'E
FhCH
,8p@
a8+~=
e%YZ
0JU,
(<.B
"J{dP
{(`[
@g~-{
#!En
=@{p
(3Hz
@R)j
yglAP
f8ZE
j'4F!
[e0X't
uCz8
sBxS<}M
5%<ZFr
2};uv
hBr-`|'
Bu5i
R #H[(
o!>N
j0Xu
;BN%
&}-F~U
*3Q,
^KV, !
ul($
mfC"
FV:"
o9@f
^zsf
QZ)^&
ogv@0
&d(N
D&")
+[eC
`}"F#
j ])
v]8]
:!4B
ZLBr:P
/H~|
.`;O
tb@\
Q(&Z>
kHgc
#L?(
<6!}
D(!*
{E#0
#u@&
T'kO
K>1Ig0.
oL`"
(X4S
P(1v0F
qYj3
O\jH
`$hX
<iFfe:Q`(y
j.dS
T$c
d_d,x
VTd`
l5dp>
=bK<
cTG(
2nHH$
$X?_
>}?p
$0[4&
=mI;F
Vf;@
Oper
!r3;<#
]v$FH
9Rf(
+!`II$
|y/K
AF-W
]V}L
ZN*W\SV
TJG2
tO_o
;KS*
Vt.vY
EM329
Untd8ql
nf|o
^Z[Y
Y_|h6u
VMT
<v,~T
@~y*2s
Hoqvtb
R?nd09
`iTZ
n~BHI
|i:X
.C"3
u<8l
rFgavc
wVs9
OH$Y
uC>Ta
0hKH
;?}S
0H~d
M8Jh
<j@'Ru
IK-N
YDa56
:iP=
SB"#@
'}W%_
8VL;i%
AZ@u~
SI`CA(
WV\D'
mq;t
4'T2
t+;G
EFou
:X:|
'S>#
o-Dq
&yLe
GM:
h('$
'g! !
}Buz
[^Y]
o+j#P
mAh@*
_Isns7u
-"5q,
P,BV
$m,'
^3Bd-
RX"U
$RSW
M_~Js
_[RZJ"
^RJ}
RsN^Lp
or-diT
~c=u;
n=t7b
LOAD
d/pC
nt]}
tx$L
!<><,
Ht[;
)u7S
"sW9
D:24
(f{B
^w@tD
"(Bf
%Yx`
D9_F
N!`(2
=lfp
9cU42Y
Ph%l?
]P+t
<ZC@
)^yXHu
${j7
a``<6
&\^r
ADAp
D;@V
,eFU
jEBp?
<~QY
cH_J
! |q
RQ@8
PQW#
C+j8
(08@
<rR'
@Ifk1
8 <~A
&Lb+
u|d
0!dv
ET~H
6Sej
`u(j
p$2FHq
AQHF
u]:q
PCRN
h%="
3\E5
<~e,@
`Pz4
S]WE
@GFP
MVCP[H
bugs@a
c9k.
1$68
rRtL
ch|R
=1"w
,)zp
{#?B
|W="L
w[_@
time
,"4D<#
erj8
"13t
t`> 1
$ 8\394\X
zd78L
h@WP
>,~L
1?L"
L3&,1/
4<9v
Xc|x<p
r=>
($:HJ
V"bEt
`"pD~L
<sn?
.d{P
3,on
ToMu
cpy6
ExA'
Unw>dE
mTsi
3Iu&
0{v)pi<J
ISd(
A)@5`<0
$hf%
43VL
pLDB&v
YArb
Z[gJ)c
oPw"D
3=5g{
Guipd
',G8o
B'JGRgZ
G9;g:
:9?C
<M=S>\?c
'$D;
2>N
5*:KH6<}
<b=w>
<RNp
c8D9<
4;?S
97l;:
48LN]
sI=N>
rJtsv
X~~N\
q&=H
d;l<p=t>x?|?
:($0,
p4>8v?
xJ:~~
<,J4
<X=\>`?d?t?
H:P;T<X=\
x~h@iMp
@9`0
;x<|=
z4|8
2p/0
P<0@
%j'f
Xtv`C
9V`Z
>rMHg
92Cz
yo<8
Sjtap
&?:P
$9):
5v=xRz
Z|wN
'$I
|$~p
fYp0:|,
Y2A$F
CZ;b
94S:X;
G`O$2e
xz%|+
t!v)x
9zG|
_'eGmgu
QfG\
PtAu
F'JGW`c
vXx~O
!;aZP
z$U|
ktzv
C?Ox
2T<9
6!:3|
0z,|
54@d
(7X?
$zM|`K
vox}
;Y%}
-hC\A
93c:
<EX6
v4x:zI|N
:A;L
<U/_
"E/O
~XT\
2?|%
tHML&
_x._
A ,$
6'P?
LPh&u
[^5YXbeH
0nQ)
_&j0
?5\A}
ldK+
W HI
=8:,
HW@X
f^s|
tKq?
PJ3W
C1M)ag
Bo8xA=w
printf
oJp>
|mlc. k
b#Mo
A'Lo
$DQp
G:h-
nle4
*{>=
tpXS
|2b3
9n#k
h[E*
?wyE
vq<b
&"[5;
j}\%A5
]f-F[
soP,j
FF3@
%wI_8f
co7d
C_p]
F.(x
vzxP
*_0)
2pRi!
&+P"xnX
Ekhf
0?N :
<B{@
=&0G
z+b:nZ
U}95
!TFL
- ]:
yN@$)T1Pe
E~v!
[8>+
[<&VSE
H,G{
RT>N
C*M#
ab6k
4=Nx$
!Q|U
LmY4
0st(
VBh9
:deI
w:"L
;r}/
bm(AWQ
PWJQ]Shm&
U+O({O
N?[q2
OB8L0~O
x<"r
r2Lf
(H_U
&^6H
%W~C
<hG-
0Rj@Q
N@K}
.Nv^
/ vX
i9vLJ
8QEgs
sv<0
UN=I(om
? l%
zLj"=$
rcb0%!
eNyd55R
-(RC
eFYq]f>cO
>kbN
vfGZ8
lJFVj
Dcn~
MJD`
]h8F
E-wP!
/fIX
lo=t
zlV&
|AaM
i;jC
cyn\
@bd?,
jH=Y
N%4tUi
>d#n
|~@=
d;,la
a>Bg
f1wY
_f=^
-F,X
ZcD@
$%zP
/a=?
f{&=O
#`4yt
X'!p
k.Bw_
o\&>^
C5*T$K
U860
xMR^YL
FKBJI
@ AZ
V={i
d:xY
#4Zo
H[.c
!gJr
Lw~ps
$suI
g/Q_
USQP0`
?#ZF
|FY<'
&)7oAhl
Rhee
(k$Sp
c87U
ARkw
viE#a
qe{.vV
cC5>
QGG*
4V"{
wLhg
F[}[
z],m
2OLL%
w`~uD*
wWB=
d-0*
/++<
tnON7
_cBb
;l|o
Up:8u
A KJ'
#[hB
f*6x8
W1y0
!/'
\u%iD,,
x> >
zp'0
EmfDJC
XY/>
u>c48
i;N#
rsIe
~|kTQ
L}nJ
c852
9YXx
o4GD
ojq"
5dU+
!ghT
3<Hrh
PUAY
_K,V4
,aCcL
Xw^yw
vriDsc
n"q-^a
p}_u2
zbd9
BBh{
)G4?-0rT
;pi+.
#=IY
[MdZD
"E\C
OH+*][
v"ZU
&wvN
-sc@2
^rYn
0zRPa
oY[3WlM
voOc
V(Qu
*Mc7!
#aQe7[
WKYF1
YU@=B
z9:g
d,X~
3J)c
, dc
NkHQ
4BTP
;/+\
-yAy
HU:=
??mz
]=JQ
T=obx$
4Tc-
k}^+&
[GuPT0y`
0VAL
'.p|Ls
tDWb
c,?]
g?m$
7Y<C
Lw*4
kT8\
Ixw`
-P$AE
m+n5G@s
v2(s?
tn=f
OF`:
;9}D
H%k8+
4AW%
JWJgY3
NKGD
'C?L
I(f)
@sY
r)vY
$vTd
=oE#
h@1B
_.gF
_8W:
H3TM
Unicode Strings:
---------------------------------------------------------------------------
jjjjj
jjjj
jjjjjj
B'B1B
jjjj
jjjj
jjjj
jjjj
jjjj
jjjj
jjjj
jjjj
ebutton
clock
combobox
edit
explorerbar
header
listview
menu
page
progress
rebar
scrollbar
spin
startpanel
status
taskband
taskbar
toolbar
tooltip
trackbar
traynotify
treeview
window
jjjjj
9-+,
jjjj
jjjjj
jjjjj
jjjj
jjjj
jjjj
jjjj
jjjjj
jjjj
jjjj
jjjjj
jjjjj
jjjjj
jjjjj
jjjj
jjjj
jjjj
jjjj
jjjjj
jjjjjjj
jjjjjjjj
jjjj
jjjj
jjjjjjj
jjjjj
jjjjj
jjjjjjjj
jjjjjjj
BBABORT
BBALL
BBCANCEL
BBCLOSE
BBHELP
BBIGNORE
BBNO
BBOK
BBRETRY
BBYES
CDROM
CLOSEDFOLDER
CURRENTFOLDER
EXECUTABLE
FLOPPY
HARD
KNOWNFILE
NETWORK
OPENFOLDER
PREVIEWGLYPH
UNKNOWNFILE
DLGTEMPLATE
DVCLAL
PACKAGEINFO
TFalertTEMPLATE
TFMAIN
TFRMalertSPYWARE
TFRMalertSPYWAREV2
XC_DEFS
MAINICON
MS Sans Serif
eWould you like to abort the removal? You can always continue the removal later on by scanning again.
Gator has been detected on your machine. While this is a known adware program, there is also a password management component included that you might be using. Would you like more information on migrating your data?{X-Cleaner needs to be updated!
Please use the update feature or visit http://www.xblock.com/ to receive the needed updates.(This program will stop functioning soon!
Scanning for %s...dThis spyware was installed with the password "%s".
Do you want to try run the configuration program?
Password Decoded!nProgram expiry has manually been disabled.
Your protection might not be up to date against the latest threats!
Continue with the removal?9This scanner should not be used on Ernst & Young systems.
LAn update is currently available.
Would you like to download and install it?
Update AvailableYHit OK when the UnInstaller has completed or when nothing happens during seve
al seconds.
Done?
Before removal
Create System Restore Point?
Removal of these programs can sometimes cause incompatiblities with other programs.
It is recommended to first make a "System Restore Point".
This enables you to "roll back" any changes later. Create it now?
Detected 'Repair failed. Please contact support.
Repair succesfully completed
Errors were detected during verification of your "Layered Service Provider" settings!
You might experience trouble using some Internet Application because of this.
Attempt repair now?
Always ignore this product?>Are you sure that you want to ignore and stop detecting "%s" ?
Scanning for %s ...cIt is recommended that you reboot your PC after the removal of software.
Do you want to reboot now?
Reboot?
@16KB instruction cache, 4-way set associative, 32 byte line size78KB data cache 2-way set associative, 32 byte line size916KB data cache, 4-way set associative, 32 byte line size
No L2 cache?Unified cache, 32 byte cache line, 4-way set associative, 128Kb?Unified cache, 32 byte cache line, 4-way set associative, 256Kb?Unified cache, 32 byte cache line, 4-way set associative, 512Kb=Unified cache, 32 byte cache line, 4-way set associative, 1Mb=Unified cache, 32 byte cache line, 4-way set associative, 2Mb
OLE error %.8x.Method '%s' not supported by automation object/Variant does not reference an automation object7Dispatch methods do not support more than 64 parameters
Could not get Windows to reboot#Error getting permissions to reboot
(Dead)
Window Background
Window Frame
Window Text
No help keyword specified.
Your system clock does not match the current time. This can cause problems with some applications.
Please correct this immediately.ASorry, this program has expired.
Please download a new version.XThis program is about to expire.
You need to obtain a new version as soon as possible.
Expire Warning
Expired!
Warning
Error=Instruction TLB, 4Kb pages, 4-way set associative, 32 entries8Instruction TLB, 4Mb pages, fully associative, 2 entries6Data TLB, 4Kb pages, 4-way set associative, 64 entries5Data TLB, 4Mb pages, 4-way set associative, 8 entries?8KB instruction cache, 4-way set associative, 32 byte line size
Caption Text
Default
Gray Text
Highlight Background
Highlight Text
Inactive Border
Inactive Caption
Inactive Caption Text
Info Background
Info Text
Menu Background
Menu Text
None
Scroll Bar
3D Dark Shadow
3D Light
Blue
Fuchsia
Aqua
White
Money Green
Sky Blue
Cream
Medium Gray
Active Border
Active Caption
Application Workspace
Background
Button Face
Button Highlight
Button Shadow
Button Text
"Unable to find a Table of Contents
No help found for %s#No context-sensitive help installed$No topic-based help system installed
Black
Maroon
Green
Olive
Navy
Purple
Teal
Gray
Silver
Lime
Yellow
Right
Down
Shift+
Ctrl+
Alt+ Clipboard does not support Icons
Cannot open clipboard
Text exceeds memo capacity/Menu '%s' is already being used by another form
Docked control must have a name%Error removing control from dock tree
- Dock zone not found
- Dock zone has no control
&Abort
&Retry
&Ignore
&All
N&o to All
Yes to &All
BkSp
Enter
Space
PgUp
PgDn
Home
Left
Abort
&All
Cannot drag a form
Metafiles
Enhanced Metafiles
Icons
Bitmaps
Warning
Error
Information
Confirm
&Yes
Cancel
&Help
"Cannot make a visible window modal
Menu index out of range
Menu inserted twice
Sub-menu is not in menu
Not enough timers available@GroupIndex cannot be less than a previous menu item's GroupIndex5Cannot create form. No MDI forms are currently active*A control cannot have itself as its parent
Cancel
&Yes
&Help
&Close
&Ignore
&Retry
Metafile is not valid!Cannot change the size of an icon
Unsupported clipboard format
Out of system resources
Canvas does not allow drawing
Invalid image size
Invalid ImageList
Invalid ImageList Index)Failed to read ImageList data from stream(Failed to write ImageList data to stream$Error creating window device context
Error creating window class+Cannot focus a disabled or invisible window!Control '%s' has no parent window
Cannot hide an MDI Child Form)Cannot change Visible in OnShow or OnHide
List index out of bounds (%d)+Out of memory while expanding memory stream
Error reading %s%s%s: %s
Stream read error
Property is read-only
Failed to create key %s
Failed to get dat
a for '%s'
Failed to set data for '%s'
Resource %s not found
%s.Seek not implemented$Operation not allowed on sorted list$%s not in a class registration group
Property %s does not exist
Stream write error
Bitmap image is not valid
Icon image is not valid
*Can't write to a read-only resource streamECheckSynchronize called from thread $%x, which is NOT the main thread
Class %s not found
A class named %s already exists%List does not allow duplicates ($0%x)#A component named %s already exists%String list does not allow duplicates
Cannot create file "%s". %s
Cannot open file "%s". %s
Invalid stream format$''%s'' is not a valid component name
Invalid property path
Invalid property value
Invalid data type for '%s' List capacity out of bounds (%d)
List count out of bounds (%d)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
Ancestor for '%s' not found
Cannot assign a %s to a %s
Bits index out of range
January
February
March
April
June
July
August
September
October
November
December
Interface not supported
Exception in safecall method
%s (%s, line %d)
Abstract Error?Access violation at address %p in module '%s'. %s of address %p
System Error. Code: %d.
A call to an OS function failed
Write$Error creating variant or safe array)Variant or safe array index out of bounds
Variant or safe array is locked
Invalid variant type conversion
Invalid variant operation%Invalid variant operation (%s%.8x)
%s5Could not convert variant of type (%s) into type (%s)=Overflow while converting variant of type (%s) into type (%s)
Variant overflow
Invalid argument
Invalid variant type
Operation not supported
Unexpected variant error
External exception %x
Assertion failed
Floating point division by zero
Floating point overflow
Floating point underflow
Invalid pointer operation
Invalid class typecast0Access violation at address %p. %s of address %p
Access violation
Stack overflow
Control-C hit
Privileged instruction(Exception %s in module %s at %p.
%s%s
Application Error1Format '%s' invalid or incompatible with argument
No argument for format '%s'"Variant method calls not supported
Read
!'%s' is not a valid integer value
Invalid argument to time encode
Invalid argument to date encode
Out of memory
I/O error %d
File not found
Invalid filename
Too many open files
File access denied
Read beyond end of file
Disk full
Invalid numeric input
Division by zero
Range check error
Integer overflow Invalid floating point operation
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
XBlock.com
FileDescription
X-Cleaner
FileVersion
1.1.1.11
InternalName
LegalCopyright
(C) 2003 by X-Block.com
LegalTrademarks
All rights reserved.
OriginalFilename
ProductName
ProductVersion
1.0.0.0
Comments
VarFileInfo
Translation
And the API's...
QUOTE
***** Installing Hooks *****
71ab6f7e GetProcAddress(accept)
71ab6f7e GetProcAddress(bind)
71ab6f7e GetProcAddress(closesocket)
71ab6f7e GetProcAddress(connect)
71ab6f7e GetProcAddress(getpeername)
71ab6f7e GetProcAddress(getsockname)
71ab6f7e GetProcAddress(getsockopt)
71ab6f7e GetProcAddress(htonl)
71ab6f7e GetProcAddress(htons)
71ab6f7e GetProcAddress(ioctlsocket)
71ab6f7e GetProcAddress(inet_addr)
71ab6f7e GetProcAddress(inet_ntoa)
71ab6f7e GetProcAddress(listen)
71ab6f7e GetProcAddress(ntohl)
71ab6f7e GetProcAddress(ntohs)
71ab6f7e GetProcAddress(recv)
71ab6f7e GetProcAddress(recvfrom)
71ab6f7e GetProcAddress(select)
71ab6f7e GetProcAddress(send)
71ab6f7e GetProcAddress(sendto)
71ab6f7e GetProcAddress(setsockopt)
71ab6f7e GetProcAddress(shutdown)
71ab6f7e GetProcAddress(socket)
71ab6f7e GetProcAddress(gethostbyaddr)
71ab6f7e GetProcAddress(gethostbyname)
71ab6f7e GetProcAddress(getprotobyname)
71ab6f7e GetProcAddress(getprotobynumber)
71ab6f7e GetProcAddress(getservbyname)
71ab6f7e GetProcAddress(getservbyport)
71ab6f7e GetProcAddress(gethostname)
71ab6f7e GetProcAddress(WSAAsyncSelect)
71ab6f7e GetProcAddress(WSAAsyncGetHostByAddr)
71ab6f7e GetProcAddress(WSAAsyncGetHostByName)
71ab6f7e GetProcAddress(WSAAsyncGetProtoByNumber)
71ab6f7e GetProcAddress(WSAAsyncGetProtoByName)
71ab6f7e GetProcAddress(WSAAsyncGetServByPort)
71ab6f7e GetProcAddress(WSAAsyncGetServByName)
71ab6f7e GetProcAddress(WSACancelAsyncRequest)
71ab6f7e GetProcAddress(WSASetBlockingHook)
71ab6f7e GetProcAddress(WSAUnhookBlockingHook)
71ab6f7e GetProcAddress(WSAGetLastError)
71ab6f7e GetProcAddress(WSASetLastError)
71ab6f7e GetProcAddress(WSACancelBlockingCall)
71ab6f7e GetProcAddress(WSAIsBlocking)
71ab6f7e GetProcAddress(WSAStartup)
71ab6f7e GetProcAddress(WSACleanup)
71ab6f7e GetProcAddress(WSAAccept)
71ab6f7e GetProcAddress(WSACloseEvent)
71ab6f7e GetProcAddress(WSAConnect)
71ab6f7e GetProcAddress(WSACreateEvent)
71ab6f7e GetProcAddress(WSADuplicateSocketA)
71ab6f7e GetProcAddress(WSADuplicateSocketW)
71ab6f7e GetProcAddress(WSAEnumNetworkEvents)
71ab6f7e GetProcAddress(WSAEnumProtocolsA)
71ab6f7e GetProcAddress(WSAEnumProtocolsW)
71ab6f7e GetProcAddress(WSAEventSelect)
71ab6f7e GetProcAddress(WSAGetOverlappedResult)
71ab6f7e GetProcAddress(WSAGetQOSByName)
71ab6f7e GetProcAddress(WSAHtonl)
71ab6f7e GetProcAddress(WSAHtons)
71ab6f7e GetProcAddress(WSAIoctl)
71ab6f7e GetProcAddress(WSAJoinLeaf)
71ab6f7e GetProcAddress(WSANtohl)
71ab6f7e GetProcAddress(WSANtohs)
71ab6f7e GetProcAddress(WSARecv)
71ab6f7e GetProcAddress(WSARecvDisconnect)
71ab6f7e GetProcAddress(WSARecvFrom)
71ab6f7e GetProcAddress(WSAResetEvent)
71ab6f7e GetProcAddress(WSASend)
71ab6f7e GetProcAddress(WSASendDisconnect)
71ab6f7e GetProcAddress(WSASendTo)
71ab6f7e GetProcAddress(WSASetEvent)
71ab6f7e GetProcAddress(WSASocketA)
71ab6f7e GetProcAddress(WSASocketW)
71ab6f7e GetProcAddress(WSAWaitForMultipleEvents)
71ab6f7e GetProcAddress(WSAAddressToStringA)
71ab6f7e GetProcAddress(WSAAddressToStringW)
71ab6f7e GetProcAddress(WSAStringToAddressA)
71ab6f7e GetProcAddress(WSAStringToAddressW)
71ab6f7e GetProcAddress(WSALookupServiceBeginA)
71ab6f7e GetProcAddress(WSALookupServiceBeginW)
71ab6f7e GetProcAddress(WSALookupServiceNextA)
71ab6f7e GetProcAddress(WSALookupServiceNextW)
71ab6f7e GetProcAddress(WSANSPIoctl)
71ab6f7e GetProcAddress(WSALookupServiceEnd)
71ab6f7e GetProcAddress(WSAInstallServiceClassA)
71ab6f7e GetProcAddress(WSAInstallServiceClassW)
71ab6f7e GetProcAddress(WSARemoveServiceClass)
71ab6f7e GetProcAddress(WSAGetServiceClassInfoA)
71ab6f7e GetProcAddress(WSAGetServiceClassInfoW)
71ab6f7e GetProcAddress(WSAEnumNameSpaceProvidersA)
71ab6f7e GetProcAddress(WSAEnumNameSpaceProvidersW)
71ab6f7e GetProcAddress(WSAGetServiceClassNameByClassIdA)
71ab6f7e GetProcAddress(WSAGetServiceClassNameByClassIdW)
71ab6f7e GetProcAddress(WSASetServiceA)
71ab6f7e GetProcAddress(WSASetServiceW)
71ab6f7e GetProcAddress(WSCDeinstallProvider)
71ab6f7e GetProcAddress(WSCInstallProvider)
71ab6f7e GetProcAddress(WSCEnumProtocols)
71ab6f7e GetProcAddress(WSCGetProviderPath)
71ab6f7e GetProcAddress(WSCInstallNameSpace)
71ab6f7e GetProcAddress(WSCUnInstallNameSpace)
71ab6f7e GetProcAddress(WSCEnableNSProvider)
71ab6f7e GetProcAddress(WPUCompleteOverlappedRequest)
71ab6f7e GetProcAddress(WSAProviderConfigChange)
71ab6f7e GetProcAddress(WSCWriteProviderOrder)
71ab6f7e GetProcAddress(WSCWriteNameSpaceOrder)
71ab6f7e GetProcAddress(WSCUpdateProvider)
71ab6f7e GetProcAddress(getaddrinfo)
71ab6f7e GetProcAddress(GetAddrInfoW)
71ab6f7e GetProcAddress(getnameinfo)
71ab6f7e GetProcAddress(GetNameInfoW)
71ab6f7e GetProcAddress(freeaddrinfo)
71ab70df RegOpenKeyExA (HKLM\System\CurrentControlSet\Services\WinSock2\Parameters)
71ab7cc4 RegOpenKeyExA (Protocol_Catalog9)
71ab737e RegOpenKeyExA (00000010)
71ab724d RegOpenKeyExA (Catalog_Entries)
71ab78ea RegOpenKeyExA (000000000001)
71ab78ea RegOpenKeyExA (000000000002)
71ab78ea RegOpenKeyExA (000000000003)
71ab78ea RegOpenKeyExA (000000000004)
71ab78ea RegOpenKeyExA (000000000005)
71ab78ea RegOpenKeyExA (000000000006)
71ab78ea RegOpenKeyExA (000000000007)
71ab78ea RegOpenKeyExA (000000000008)
71ab78ea RegOpenKeyExA (000000000009)
71ab78ea RegOpenKeyExA (000000000010)
71ab78ea RegOpenKeyExA (000000000011)
71ab78ea RegOpenKeyExA (000000000012)
71ab78ea RegOpenKeyExA (000000000013)
71ab78ea RegOpenKeyExA (000000000014)
71ab78ea RegOpenKeyExA (000000000015)
71ab78ea RegOpenKeyExA (000000000016)
71ab78ea RegOpenKeyExA (000000000017)
71ab78ea RegOpenKeyExA (000000000018)
71ab78ea RegOpenKeyExA (000000000019)
71ab78ea RegOpenKeyExA (000000000020)
71ab78ea RegOpenKeyExA (000000000021)
71ab78ea RegOpenKeyExA (000000000022)
71ab78ea RegOpenKeyExA (000000000023)
71ab2623 WaitForSingleObject(778,0)
71ab83c6 RegOpenKeyExA (NameSpace_Catalog5)
71ab737e RegOpenKeyExA (00000004)
71ab7f5b RegOpenKeyExA (Catalog_Entries)
71ab80ef RegOpenKeyExA (000000000001)
71ab80ef RegOpenKeyExA (000000000002)
71ab80ef RegOpenKeyExA (000000000003)
71ab2623 WaitForSingleObject(770,0)
71aa1afa RegOpenKeyExA (HKLM\System\CurrentControlSet\Services\Winsock2\Parameters)
71aa1996 GlobalAlloc()
7c80b689 ExitThread()
7c80b729 GetModuleHandleA((null))
19c07a GetModuleHandleA(kernel32.dll)
19c090 GetProcAddress(VirtualAlloc)
19c0a4 GetProcAddress(VirtualFree)
19c4ac GetModuleHandleA(kernel32.dll)
19c513 GetProcAddress(GetCurrentThreadId)
19c513 GetProcAddress(DeleteCriticalSection)
19c513 GetProcAddress(LeaveCriticalSection)
19c513 GetProcAddress(EnterCriticalSection)
19c513 GetProcAddress(InitializeCriticalSection)
19c513 GetProcAddress(VirtualFree)
19c513 GetProcAddress(VirtualAlloc)
19c513 GetProcAddress(LocalFree)
19c513 GetProcAddress(LocalAlloc)
19c513 GetProcAddress(VirtualQuery)
19c513 GetProcAddress(WideCharToMultiByte)
19c513 GetProcAddress(MultiByteToWideChar)
19c513 GetProcAddress(lstrlenA)
19c513 GetProcAddress(lstrcpyA)
19c513 GetProcAddress(LoadLibraryExA)
19c513 GetProcAddress(GetThreadLocale)
19c513 GetProcAddress(GetStartupInfoA)
19c513 GetProcAddress(GetModuleFileNameA)
19c513 GetProcAddress(GetLocaleInfoA)
19c513 GetProcAddress(GetLastError)
19c513 GetProcAddress(GetCommandLineA)
19c513 GetProcAddress(FreeLibrary)
19c513 GetProcAddress(ExitProcess)
19c513 GetProcAddress(WriteFile)
19c513 GetProcAddress(SetFilePointer)
19c513 GetProcAddress(SetEndOfFile)
19c513 GetProcAddress(RtlUnwind)
19c513 GetProcAddress(ReadFile)
19c513 GetProcAddress(RaiseException)
19c513 GetProcAddress(GetStdHandle)
19c513 GetProcAddress(GetFileSize)
19c513 GetProcAddress(GetSystemTime)
19c513 GetProcAddress(GetFileType)
19c513 GetProcAddress(CreateFileA)
19c513 GetProcAddress(CloseHandle)
19c4ac GetModuleHandleA(user32.dll)
19c513 GetProcAddress(GetKeyboardType)
19c513 GetProcAddress(LoadStringA)
19c513 GetProcAddress(MessageBoxA)
19c4ac GetModuleHandleA(advapi32.dll)
19c513 GetProcAddress(RegQueryValueExA)
19c513 GetProcAddress(RegOpenKeyExA)
19c513 GetProcAddress(RegCloseKey)
19c4ac GetModuleHandleA(oleaut32.dll)
19c513 GetProcAddress(VariantChangeTypeEx)
19c513 GetProcAddress(VariantCopyInd)
19c513 GetProcAddress(VariantClear)
19c513 GetProcAddress(SysStringLen)
19c513 GetProcAddress(SysFreeString)
19c513 GetProcAddress(SysAllocStringLen)
19c4ac GetModuleHandleA(kernel32.dll)
19c513 GetProcAddress(TlsSetValue)
19c513 GetProcAddress(TlsGetValue)
19c513 GetProcAddress(TlsFree)
19c513 GetProcAddress(TlsAlloc)
19c513 GetProcAddress(LocalFree)
19c513 GetProcAddress(LocalAlloc)
19c513 GetProcAddress(GetModuleFileNameA)
19c4ac GetModuleHandleA(advapi32.dll)
19c513 GetProcAddress(RegSetValueExA)
19c513 GetProcAddress(RegSetValueA)
19c513 GetProcAddress(RegQueryValueExA)
19c513 GetProcAddress(RegQueryInfoKeyA)
19c513 GetProcAddress(RegOpenKeyExA)
19c513 GetProcAddress(RegEnumKeyExA)
19c513 GetProcAddress(RegCloseKey)
19c4ac GetModuleHandleA(kernel32.dll)
19c513 GetProcAddress(VirtualQuery)
19c513 GetProcAddress(UnmapViewOfFile)
19c513 GetProcAddress(UnhandledExceptionFilter)
19c513 GetProcAddress(MapViewOfFile)
19c513 GetProcAddress(LockResource)
19c513 GetProcAddress(LoadResource)
19c513 GetProcAddress(GlobalFree)
19c513 GetProcAddress(GlobalAlloc)
19c513 GetProcAddress(GetVolumeInformationA)
19c513 GetProcAddress(GetVersionExA)
19c513 GetProcAddress(GetVersion)
19c513 GetProcAddress(GetThreadLocale)
19c513 GetProcAddress(GetProcAddress)
19c513 GetProcAddress(GetModuleHandleA)
19c513 GetProcAddress(GetModuleFileNameA)
19c513 GetProcAddress(GetLocaleInfoA)
19c513 GetProcAddress(GetLocalTime)
19c513 GetProcAddress(GetDriveTypeA)
19c513 GetProcAddress(GetDiskFreeSpaceA)
19c513 GetProcAddress(GetCurrentProcessId)
19c513 GetProcAddress(GetCurrentProcess)
19c513 GetProcAddress(GetCommandLineA)
19c513 GetProcAddress(GetCPInfo)
19c513 GetProcAddress(FindResourceA)
19c513 GetProcAddress(ExitProcess)
19c513 GetProcAddress(EnumCalendarInfoA)
19c513 GetProcAddress(CreateFileMappingA)
19c513 GetProcAddress(CreateFileA)
19c513 GetProcAddress(CloseHandle)
19c4ac GetModuleHandleA(user32.dll)
19c513 GetProcAddress(MessageBoxA)
19c513 GetProcAddress(LoadStringA)
19c513 GetProcAddress(GetSystemMetrics)
19c513 GetProcAddress(FindWindowA)
19c513 GetProcAddress(DialogBoxIndirectParamA)
19c4ac GetModuleHandleA(ole32.dll)
19c513 GetProcAddress(CoCreateGuid)
184063 RegOpenKeyExA (HKCU\Software\Borland\Locales)
184081 RegOpenKeyExA (HKCU\Software\Borland\Delphi\Locales)
184e9d GetCommandLineA()
5ad8ef89 GetCurrentProcessId()=3964
5ad7b1ba IsDebuggerPresent()
187eb7 GetVersionExA()
18846f GetModuleHandleA(kernel32.dll)
188480 GetProcAddress(GetDiskFreeSpaceExA)
182667 GetSystemTime()
191a43 GetModuleHandleA((null))
191a7d GetVersionExA()
191aac GetCurrentProcessId()=3964
191ac8 GetCommandLineA()
191674 GetModuleHandleA(kernel32.dll)
191692 GetProcAddress(IsDebuggerPresent)
19169c IsDebuggerPresent()
191247 GlobalAlloc()
191275 GetModuleHandleA(ntdll.dll)
191299 GetProcAddress(NtQuerySystemInformation)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(DeleteCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LeaveCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(EnterCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(InitializeCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(VirtualFree)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(VirtualAlloc)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LocalFree)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LocalAlloc)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetTickCount)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(QueryPerformanceCounter)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetCurrentThreadId)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(InterlockedDecrement)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(InterlockedIncrement)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(VirtualQuery)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(WideCharToMultiByte)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(MultiByteToWideChar)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(lstrlenA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(lstrcpynA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LoadLibraryExA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetThreadLocale)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetStartupInfoA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetModuleFileNameA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetLocaleInfoA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetLastError)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FreeLibrary)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FindFirstFileA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FindClose)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(ExitProcess)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(WriteFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(UnhandledExceptionFilter)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetFilePointer)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetEndOfFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(RtlUnwind)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(ReadFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(RaiseException)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetStdHandle)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetFileSize)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetFileType)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CreateFileA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CloseHandle)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetKeyboardType)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(LoadStringA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(MessageBoxA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CharNextA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegQueryValueExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegOpenKeyExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegCloseKey)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SysFreeString)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SysReAllocStringLen)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SysAllocStringLen)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(TlsSetValue)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(TlsGetValue)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LocalAlloc)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegSetValueExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegQueryValueExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegQueryInfoKeyA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegOpenKeyExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegFlushKey)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegEnumValueA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegEnumKeyExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegDeleteValueA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegDeleteKeyA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegCreateKeyExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegCloseKey)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(OpenProcessToken)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(LookupPrivilegeValueA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(AdjustTokenPrivileges)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(lstrcpyA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(WriteFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(WaitForSingleObject)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(VirtualQuery)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(VirtualAlloc)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(UnmapViewOfFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(TerminateProcess)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(Sleep)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SizeofResource)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetThreadLocale)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetFileTime)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetFilePointer)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetFileAttributesA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetEvent)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetErrorMode)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetEndOfFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SearchPathA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(ResetEvent)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(RemoveDirectoryA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(ReadFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(OpenProcess)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(MultiByteToWideChar)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(MulDiv)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(MoveFileExA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(MapViewOfFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LocalFileTimeToFileTime)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LoadResource)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LoadLibraryA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LeaveCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(InitializeCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalUnlock)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalReAlloc)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalHandle)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalLock)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalFree)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalFindAtomA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalDeleteAtom)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalAlloc)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalAddAtomA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetWindowsDirectoryA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetVolumeInformationA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetVersionExA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetTickCount)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetThreadLocale)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetSystemInfo)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetSystemDirectoryA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetStringTypeExA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetStdHandle)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetShortPathNameA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetModuleFileNameA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetLocaleInfoA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetLocalTime)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetLastError)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetFullPathNameA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetFileSize)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetFileAttributesA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetExitCodeProcess)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetEnvironmentVariableA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetDriveTypeA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetDiskFreeSpaceA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetDateFormatA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetCurrentThreadId)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetComputerNameA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetCPInfo)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetACP)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(InterlockedExchange)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FreeLibrary)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FormatMessageA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FindResourceA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FindNextFileA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FindFirstFileA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FindClose)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FileTimeToLocalFileTime)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FileTimeToDosDateTime)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(ExpandEnvironmentStringsA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(EnumCalendarInfoA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(EnterCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(DosDateTimeToFileTime)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(DeleteFileA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(DeleteCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CreateThread)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CreateProcessA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CreateFileMappingA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CreateFileA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CreateEventA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CompareStringA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CloseHandle)
192f29 GetModuleHandleA(version.dll)
192f39 GetProcAddress(VerQueryValueA)
192f29 GetModuleHandleA(version.dll)
192f39 GetProcAddress(GetFileVersionInfoSizeA)
192f29 GetModuleHandleA(version.dll)
192f39 GetProcAddress(GetFileVersionInfoA)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(UnrealizeObject)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(StretchBlt)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetWindowOrgEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetWinMetaFileBits)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetViewportOrgEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetTextColor)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetStretchBltMode)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetROP2)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetPixel)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetEnhMetaFileBits)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetDIBColorTable)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetBrushOrgEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetBkMode)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetBkColor)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SelectPalette)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SelectObject)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SaveDC)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(RoundRect)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(RestoreDC)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(Rectangle)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(RectVisible)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(RealizePalette)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(Polyline)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(PlayEnhMetaFile)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(PatBlt)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(MoveToEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(MaskBlt)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(LineTo)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(IntersectClipRect)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetWindowOrgEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetWinMetaFileBits)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetTextMetricsA)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetTextExtentPointA)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetTextExtentPoint32A)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetSystemPaletteEntries)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetStockObject)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetPixel)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetPaletteEntries)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetObjectA)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetEnhMetaFilePaletteEntries)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetEnhMetaFileHeader)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetEnhMetaFileBits)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetDeviceCaps)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetDIBits)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetDIBColorTable)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetDCOrgEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetCurrentPositionEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetClipBox)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetBrushOrgEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetBitmapBits)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(ExcludeClipRect)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(Ellipse)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(DeleteObject)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(DeleteEnhMetaFile)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(DeleteDC)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateSolidBrush)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreatePenIndirect)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreatePalette)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateHalftonePalette)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateFontIndirectA)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateDIBitmap)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateDIBSection)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateCompatibleDC)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateCompatibleBitmap)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateBrushIndirect)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateBitmap)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CopyEnhMetaFileA)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(BitBlt)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CreateWindowExA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(WindowFromPoint)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(WinHelpA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(WaitMessage)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(UpdateWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(UnregisterClassA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(UnhookWindowsHookEx)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(TranslateMessage)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(TranslateMDISysAccel)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(TrackPopupMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SystemParametersInfoA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ShowWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ShowScrollBar)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ShowOwnedPopups)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ShowCursor)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetWindowsHookExA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetWindowTextA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetWindowPos)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetWindowPlacement)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetWindowLongA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetTimer)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetScrollRange)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetScrollPos)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetScrollInfo)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetPropA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetParent)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetMenuItemInfoA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetForegroundWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetFocus)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetCursor)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetClipboardData)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetClassLongA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetCapture)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetActiveWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SendMessageA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ScrollWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ScreenToClient)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(RemovePropA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(RemoveMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ReleaseDC)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ReleaseCapture)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(RegisterWindowMessageA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(RegisterClipboardFormatA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(RegisterClassA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(RedrawWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(PtInRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(PostQuitMessage)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(PostMessageA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(PeekMessageA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(OpenClipboard)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(OffsetRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(OemToCharA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(MessageBoxA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(MessageBeep)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(MapWindowPoints)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(MapVirtualKeyA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(LoadStringA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(LoadKeyboardLayoutA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(LoadIconA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(LoadCursorA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(LoadBitmapA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(KillTimer)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsZoomed)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsWindowVisible)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsWindowEnabled)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsRectEmpty)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsIconic)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsDialogMessageA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsChild)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(InvalidateRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IntersectRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(InsertMenuItemA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(InsertMenuA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(InflateRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowThreadProcessId)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowTextA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowPlacement)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowModuleFileNameA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowLongA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowDC)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetTopWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetSystemMetrics)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetSystemMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetSysColorBrush)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetSysColor)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetSubMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetScrollRange)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetScrollPos)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetScrollInfo)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetPropA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetParent)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetMenuStringA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetMenuState)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetMenuItemInfoA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetMenuItemID)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetMenuItemCount)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetLastActivePopup)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetKeyboardState)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetKeyboardLayoutList)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetKeyboardLayout)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetKeyState)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetKeyNameTextA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetIconInfo)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetForegroundWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetFocus)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetDesktopWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetDCEx)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetDC)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetCursorPos)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetCursor)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetClipboardData)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetClientRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetClassNameA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetClassInfoA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetCapture)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetActiveWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(FrameRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(FindWindowA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(FillRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ExitWindowsEx)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EqualRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EnumWindows)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EnumThreadWindows)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EndPaint)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EnableWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EnableScrollBar)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EnableMenuItem)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EmptyClipboard)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DrawTextA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DrawMenuBar)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DrawIconEx)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DrawIcon)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DrawFrameControl)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DrawEdge)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DispatchMessageA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DestroyWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DestroyMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DestroyIcon)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DestroyCursor)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DeleteMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DefWindowProcA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DefMDIChildProcA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DefFrameProcA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CreatePopupMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CreateMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CreateIcon)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CloseClipboard)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ClientToScreen)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CheckMenuItem)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CallWindowProcA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CallNextHookEx)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(BeginPaint)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CharNextA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CharLowerBuffA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CharLowerA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CharUpperBuffA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CharToOemA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(AdjustWindowRectEx)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ActivateKeyboardLayout)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(Sleep)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SafeArrayPtrOfIndex)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SafeArrayGetUBound)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SafeArrayGetLBound)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SafeArrayCreate)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(VariantChangeType)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(VariantCopy)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(VariantClear)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(VariantInit)
192f29 GetModuleHandleA(ole32.dll)
192f39 GetProcAddress(CoUninitialize)
192f29 GetModuleHandleA(ole32.dll)
192f39 GetProcAddress(CoInitialize)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(GetErrorInfo)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SysFreeString)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_SetIconSize)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_GetIconSize)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Write)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Read)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_GetDragImage)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_DragShowNolock)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_SetDragCursorImage)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_DragMove)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_DragLeave)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_DragEnter)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_EndDrag)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_BeginDrag)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Remove)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_DrawEx)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Draw)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_GetBkColor)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_SetBkColor)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_ReplaceIcon)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Add)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_GetImageCount)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Destroy)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Create)
192f29 GetModuleHandleA(shell32.dll)
192f39 GetProcAddress(ShellExecuteA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetSetOptionA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetReadFile)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetQueryOptionA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetOpenUrlA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetOpenA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetErrorDlg)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetConnectA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetCloseHandle)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(HttpSendRequestA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(HttpQueryInfoA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(HttpOpenRequestA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(QueryServiceStatus)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(OpenServiceA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(OpenSCManagerA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(DeleteService)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(ControlService)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(CloseServiceHandle)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(ChangeServiceConfigA)
191fae CreateFileA(\\.\SICE)
191fae CreateFileA(\\.\NTICE)
191fae CreateFileA(\\.\SIWVID)
189575 RegSetValueA (HKCR\.key,)
77e0723f RegCreateKeyExA (.key,(null))
77de6fb8 RegSetValueExA ((null))
1895ac RegOpenKeyExA (HKCR\.key)
1895d6 RegSetValueExA ()
191cdf GetModuleHandleA((null))
406077 RegOpenKeyExA (HKCU\Software\Borland\Locales)
406095 RegOpenKeyExA (HKLM\Software\Borland\Locales)
4060b3 RegOpenKeyExA (HKCU\Software\Borland\Delphi\Locales)
40d267 GetVersionExA()
191c87 GetModuleHandleA(kernel32.dll)
1917c9 GetProcAddress(GetDiskFreeSpaceExA)
191c87 GetModuleHandleA(oleaut32.dll)
1917c9 GetProcAddress(VariantChangeTypeEx)
1917c9 GetProcAddress(VarNeg)
1917c9 GetProcAddress(VarNot)
1917c9 GetProcAddress(VarAdd)
1917c9 GetProcAddress(VarSub)
1917c9 GetProcAddress(VarMul)
1917c9 GetProcAddress(VarDiv)
1917c9 GetProcAddress(VarIdiv)
1917c9 GetProcAddress(VarMod)
1917c9 GetProcAddress(VarAnd)
1917c9 GetProcAddress(VarOr)
1917c9 GetProcAddress(VarXor)
1917c9 GetProcAddress(VarCmp)
1917c9 GetProcAddress(VarI4FromStr)
1917c9 GetProcAddress(VarR4FromStr)
1917c9 GetProcAddress(VarR8FromStr)
1917c9 GetProcAddress(VarDateFromStr)
1917c9 GetProcAddress(VarCyFromStr)
1917c9 GetProcAddress(VarBoolFromStr)
1917c9 GetProcAddress(VarBstrFromCy)
1917c9 GetProcAddress(VarBstrFromDate)
1917c9 GetProcAddress(VarBstrFromBool)
191c87 GetModuleHandleA(USER32.DLL)
1917c9 GetProcAddress(GetMonitorInfoA)
1917c9 GetProcAddress(GetSystemMetrics)
1917c9 GetProcAddress(EnumDisplayMonitors)
74723bee GetModuleHandleA(C:\WINDOWS\system32\ntdll.dll)
74723b62 GetProcAddress(NtQueryInformationProcess)
747226aa GetVersionExA()
74723bee GetModuleHandleA(C:\WINDOWS\system32\imm32.dll)
7472279f GetProcAddress(CtfImmCoUninitialize)
747227dc GetProcAddress(CtfImmLastEnabledWndDestroy)
7472281f GetProcAddress(CtfImmSetCiceroStartInThread)
74722864 GetProcAddress(CtfImmIsCiceroStartedInThread)
747228a9 GetProcAddress(CtfImmIsCiceroEnabled)
747228e5 GetProcAddress(CtfImmIsTextFrameServiceDisabled)
7472292c GetProcAddress(CtfImmEnterCoInitCountSkipMode)
74722972 GetProcAddress(CtfImmLeaveCoInitCountSkipMode)
747229b6 GetProcAddress(ImmGetDefaultIMEWnd)
747229ef GetProcAddress(ImmReleaseContext)
74722a29 GetProcAddress(ImmNotifyIME)
74722a5c GetProcAddress(ImmSetConversionStatus)
74722a9a GetProcAddress(ImmGetConversionStatus)
74722ad6 GetProcAddress(ImmGetProperty)
74722b0a GetProcAddress(ImmGetOpenStatus)
74722b40 GetProcAddress(ImmGetContext)
74722b75 GetProcAddress(ImmSetOpenStatus)
74722bac GetProcAddress(ImmInstallIMEA)
74722be2 GetProcAddress(ImmGetDescriptionA)
74722c1a GetProcAddress(ImmGetDescriptionW)
74722c52 GetProcAddress(ImmGetIMEFileNameA)
74722c8a GetProcAddress(ImmGetIMEFileNameW)
74723168 GetProcAddress(ImmSetHotKey)
747230a7 RegOpenKeyExA (HKLM\SOFTWARE\Microsoft\CTF\Compatibility\xclean_micro.exe)
747230a7 RegOpenKeyExA (HKLM\SOFTWARE\Microsoft\CTF\SystemShared\)
7472245b CreateMutex(CTF.LBES.MutexDefaultS-1-5-21-823518204-776561741-839522115-1003)
7472245b CreateMutex(CTF.Compart.MutexDefaultS-1-5-21-823518204-776561741-839522115-1003)
7472245b CreateMutex(CTF.Asm.MutexDefaultS-1-5-21-823518204-776561741-839522115-1003)
7472245b CreateMutex(CTF.Layouts.MutexDefaultS-1-5-21-823518204-776561741-839522115-1003)
7472245b CreateMutex(CTF.TMD.MutexDefaultS-1-5-21-823518204-776561741-839522115-1003)
747230a7 RegOpenKeyExA (HKCU\Keyboard Layout\Toggle)
747226aa GetVersionExA()
74723bee GetModuleHandleA(C:\WINDOWS\system32\KERNEL32)
74722d2b GetProcAddress(GetUserDefaultUILanguage)
7472260a RegOpenKeyExA (HKLM\SOFTWARE\Microsoft\CTF\)
74724683 GetCurrentProcessId()=3964
7472245b CreateMutex(CTF.TimListCache.FMPDefaultS-1-5-21-823518204-776561741-839522115-1003MUTEX.DefaultS-1-5-21-823518204-776561741-839522115-1003)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7475556a GetCurrentProcessId()=3964
7473d232 WaitForSingleObject(740,1388)
763985f8 GetProcAddress(GetFileVersionInfoW)
7639860d GetProcAddress(GetFileVersionInfoSizeW)
76398622 GetProcAddress(VerQueryValueW)
7c816513 WaitForSingleObject(738,64)
755d8f33 GetVersionExA()
755e5225 GetVersionExA()
755dd4f4 LoadLibraryA(C:\WINDOWS\system32\ole32.dll)=774e0000
755da32e GetProcAddress(CoCreateInstance)
763a3b62 GetProcAddress(CtfImeCreateThreadMgr)
763a3b7c GetProcAddress(CtfImeDestroyThreadMgr)
763a3b96 GetProcAddress(CtfImeCreateInputContext)
763a3bac GetProcAddress(CtfImeDestroyInputContext)
763a3bc2 GetProcAddress(CtfImeSetActiveContextAlways)
763a3bd8 GetProcAddress(CtfImeProcessCicHotkey)
763a3bee GetProcAddress(CtfImeDispatchDefImeMessage)
763a3c04 GetProcAddress(CtfImeIsIME)
755dd4a4 GetModuleHandleA(C:\WINDOWS\system32\ntdll.dll)
755d8acc GetProcAddress(RtlDllShutdownInProgress)
7c816513 WaitForSingleObject(738,64)
7639722d GetProcAddress(ImeInquire)
76397242 GetProcAddress(ImeConversionList)
76397257 GetProcAddress(ImeRegisterWord)
7639726c GetProcAddress(ImeUnregisterWord)
76397281 GetProcAddress(ImeGetRegisterWordStyle)
76397296 GetProcAddress(ImeEnumRegisterWord)
763972ab GetProcAddress(ImeConfigure)
763972c0 GetProcAddress(ImeDestroy)
763972d5 GetProcAddress(ImeEscape)
763972ea GetProcAddress(ImeProcessKey)
763972ff GetProcAddress(ImeSelect)
76397314 GetProcAddress(ImeSetActiveContext)
7639732c GetProcAddress(ImeToAsciiEx)
76397344 GetProcAddress(NotifyIME)
7639735c GetProcAddress(ImeSetCompositionString)
76397374 GetProcAddress(ImeGetImeMenuItems)
763973b4 GetProcAddress(CtfImeInquireExW)
763973c8 GetProcAddress(CtfImeSelectEx)
763973dc GetProcAddress(CtfImeEscapeEx)
763973f0 GetProcAddress(CtfImeGetGuidAtom)
76397404 GetProcAddress(CtfImeIsGuidMapEnable)
191c87 GetModuleHandleA(USER32)
1917c9 GetProcAddress(AnimateWindow)
191c87 GetModuleHandleA(comctl32.dll)
1917c9 GetProcAddress(InitializeFlatSB)
1917c9 GetProcAddress(UninitializeFlatSB)
1917c9 GetProcAddress(FlatSB_GetScrollProp)
1917c9 GetProcAddress(FlatSB_SetScrollProp)
1917c9 GetProcAddress(FlatSB_EnableScrollBar)
1917c9 GetProcAddress(FlatSB_ShowScrollBar)
1917c9 GetProcAddress(FlatSB_GetScrollRange)
1917c9 GetProcAddress(FlatSB_GetScrollInfo)
1917c9 GetProcAddress(FlatSB_GetScrollPos)
1917c9 GetProcAddress(FlatSB_SetScrollPos)
1917c9 GetProcAddress(FlatSB_SetScrollInfo)
1917c9 GetProcAddress(FlatSB_SetScrollRange)
191c87 GetModuleHandleA(User32.dll)
1917c9 GetProcAddress(SetLayeredWindowAttributes)
191c87 GetModuleHandleA(ole32.dll)
1917c9 GetProcAddress(CoCreateInstanceEx)
1917c9 GetProcAddress(CoInitializeEx)
1917c9 GetProcAddress(CoAddRefServerProcess)
1917c9 GetProcAddress(CoReleaseServerProcess)
1917c9 GetProcAddress(CoResumeClassObjects)
1917c9 GetProcAddress(CoSuspendClassObjects)
191c87 GetModuleHandleA(kernel32.dll)
465284 LoadLibraryA(shell32.dll)=7c9c0000
1917c9 GetProcAddress(SHEmptyRecycleBinA)
4652b1 LoadLibraryA(user32.dll)=7e410000
1917c9 GetProcAddress(GetWindowModuleFileNameA)
42ecf1 RegOpenKeyExA (HKCU\Software\X-Cleaner)
403448 CreateFileA(C:\UBCD4Win\306-test\plugin\AntiSpyware\XBlock\xclean_micro.exe)
402f19 ReadFile()
42ecf1 RegOpenKeyExA (HKCU\Software\X-Cleaner)
1917c9 GetProcAddress(MonitorFromWindow)
773d3f9f LoadLibraryA(UxTheme.dll)=5ad70000
773d4000 GetProcAddress(EnableThemeDialogTexture)
773d4000 GetProcAddress(OpenThemeData)
7473d232 WaitForSingleObject(74c,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(754,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
773d4000 GetProcAddress(IsThemeBackgroundPartiallyTransparent)
773d4000 GetProcAddress(DrawThemeParentBackground)
773ea491 GetCurrentProcessId()=3964
773d4000 GetProcAddress(DrawThemeBackground)
773ea491 GetCurrentProcessId()=3964
773d4000 GetProcAddress(GetThemeBackgroundContentRect)
773d4000 GetProcAddress(DrawThemeText)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
747230a7 RegOpenKeyExA (HKCU\Keyboard Layout\Toggle)
7473d232 WaitForSingleObject(754,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(754,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(754,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
747230a7 RegOpenKeyExA (HKCU\SOFTWARE\Microsoft\CTF\LangBarAddIn\)
747230a7 RegOpenKeyExA (HKLM\SOFTWARE\Microsoft\CTF\LangBarAddIn\)
7473d232 WaitForSingleObject(754,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7472245b CreateMutex(MSCTF.Shared.MUTEX.ABF)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
74723bee GetModuleHandleA(C:\WINDOWS\system32\ntdll.dll)
7475ee00 GetProcAddress(RtlDllShutdownInProgress)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7c341e17 GetVersionExA()
7c341897 GetModuleHandleA(kernel32.dll)
7c3418ab GetProcAddress(InitializeCriticalSectionAndSpinCount)
7c34193c GetModuleHandleA(kernel32.dll)
7c341950 GetProcAddress(FlsAlloc)
7c34195d GetProcAddress(FlsGetValue)
7c34196a GetProcAddress(FlsSetValue)
7c341977 GetProcAddress(FlsFree)
7c341e95 GetCommandLineA()
7c341fc6 GetModuleHandleA(KERNEL32)
7c341fda GetProcAddress(IsProcessorFeaturePresent)
773d4000 GetProcAddress(HitTestThemeBackground)
773ea491 GetCurrentProcessId()=3964
773ea491 GetCurrentProcessId()=3964
773ea491 GetCurrentProcessId()=3964
773ea491 GetCurrentProcessId()=3964
773ea491 GetCurrentProcessId()=3964
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
773d4000 GetProcAddress(CloseThemeData)
407873 GlobalAlloc()
42a74b LoadLibraryA(uxtheme.dll)=5ad70000
1917c9 GetProcAddress(OpenThemeData)
1917c9 GetProcAddress(CloseThemeData)
1917c9 GetProcAddress(DrawThemeBackground)
1917c9 GetProcAddress(DrawThemeText)
1917c9 GetProcAddress(GetThemeBackgroundContentRect)
1917c9 GetProcAddress(GetThemeBackgroundContentRect)
1917c9 GetProcAddress(GetThemePartSize)
1917c9 GetProcAddress(GetThemeTextExtent)
1917c9 GetProcAddress(GetThemeTextMetrics)
1917c9 GetProcAddress(GetThemeBackgroundRegion)
1917c9 GetProcAddress(HitTestThemeBackground)
1917c9 GetProcAddress(DrawThemeEdge)
1917c9 GetProcAddress(DrawThemeIcon)
1917c9 GetProcAddress(IsThemePartDefined)
1917c9 GetProcAddress(IsThemeBackgroundPartiallyTransparent)
1917c9 GetProcAddress(GetThemeColor)
1917c9 GetProcAddress(GetThemeMetric)
1917c9 GetProcAddress(GetThemeString)
1917c9 GetProcAddress(GetThemeBool)
1917c9 GetProcAddress(GetThemeInt)
1917c9 GetProcAddress(GetThemeEnumValue)
1917c9 GetProcAddress(GetThemePosition)
1917c9 GetProcAddress(GetThemeFont)
1917c9 GetProcAddress(GetThemeRect)
1917c9 GetProcAddress(GetThemeMargins)
1917c9 GetProcAddress(GetThemeIntList)
1917c9 GetProcAddress(GetThemePropertyOrigin)
1917c9 GetProcAddress(SetWindowTheme)
1917c9 GetProcAddress(GetThemeFilename)
1917c9 GetProcAddress(GetThemeSysColor)
1917c9 GetProcAddress(GetThemeSysColorBrush)
1917c9 GetProcAddress(GetThemeSysBool)
1917c9 GetProcAddress(GetThemeSysSize)
1917c9 GetProcAddress(GetThemeSysFont)
1917c9 GetProcAddress(GetThemeSysString)
1917c9 GetProcAddress(GetThemeSysInt)
1917c9 GetProcAddress(IsThemeActive)
1917c9 GetProcAddress(IsAppThemed)
1917c9 GetProcAddress(GetWindowTheme)
1917c9 GetProcAddress(EnableThemeDialogTexture)
1917c9 GetProcAddress(IsThemeDialogTextureEnabled)
1917c9 GetProcAddress(GetThemeAppProperties)
1917c9 GetProcAddress(SetThemeAppProperties)
1917c9 GetProcAddress(GetCurrentThemeName)
1917c9 GetProcAddress(GetThemeDocumentationProperty)
1917c9 GetProcAddress(DrawThemeParentBackground)
1917c9 GetProcAddress(EnableTheming)
7473d232 WaitForSingleObject(740,1388)
7473d91c OpenProcess(pid=1572)
7472245b CreateMutex(MSCTF.Shared.MUTEX.EJI)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(740,1388)
7473f824 WaitForSingleObject(720,0)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(740,1388)
7473f824 WaitForSingleObject(720,0)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(71c,1388)
42f50c RegOpenKeyExA (HKLM\SOFTWARE\Ernst & Young\Loadset)
40494b ExitProcess()
755d9a75 GetProcAddress(TF_DllDetachInOther)
74721d36 GetCurrentProcessId()=3964
74722056 GetCurrentProcessId()=3964
74724683 GetCurrentProcessId()=3964
7475556a GetCurrentProcessId()=3964
5ad7adb2 GetCurrentProcessId()=3964
***** Injected Process Terminated *****
7ca26a01 GetCurrentProcessId()=3964
7ca2aa8b GetProcAddress(ReleaseActCtx)
7745b606 GetProcAddress(ReleaseActCtx)
71ab6f7e GetProcAddress(accept)
71ab6f7e GetProcAddress(bind)
71ab6f7e GetProcAddress(closesocket)
71ab6f7e GetProcAddress(connect)
71ab6f7e GetProcAddress(getpeername)
71ab6f7e GetProcAddress(getsockname)
71ab6f7e GetProcAddress(getsockopt)
71ab6f7e GetProcAddress(htonl)
71ab6f7e GetProcAddress(htons)
71ab6f7e GetProcAddress(ioctlsocket)
71ab6f7e GetProcAddress(inet_addr)
71ab6f7e GetProcAddress(inet_ntoa)
71ab6f7e GetProcAddress(listen)
71ab6f7e GetProcAddress(ntohl)
71ab6f7e GetProcAddress(ntohs)
71ab6f7e GetProcAddress(recv)
71ab6f7e GetProcAddress(recvfrom)
71ab6f7e GetProcAddress(select)
71ab6f7e GetProcAddress(send)
71ab6f7e GetProcAddress(sendto)
71ab6f7e GetProcAddress(setsockopt)
71ab6f7e GetProcAddress(shutdown)
71ab6f7e GetProcAddress(socket)
71ab6f7e GetProcAddress(gethostbyaddr)
71ab6f7e GetProcAddress(gethostbyname)
71ab6f7e GetProcAddress(getprotobyname)
71ab6f7e GetProcAddress(getprotobynumber)
71ab6f7e GetProcAddress(getservbyname)
71ab6f7e GetProcAddress(getservbyport)
71ab6f7e GetProcAddress(gethostname)
71ab6f7e GetProcAddress(WSAAsyncSelect)
71ab6f7e GetProcAddress(WSAAsyncGetHostByAddr)
71ab6f7e GetProcAddress(WSAAsyncGetHostByName)
71ab6f7e GetProcAddress(WSAAsyncGetProtoByNumber)
71ab6f7e GetProcAddress(WSAAsyncGetProtoByName)
71ab6f7e GetProcAddress(WSAAsyncGetServByPort)
71ab6f7e GetProcAddress(WSAAsyncGetServByName)
71ab6f7e GetProcAddress(WSACancelAsyncRequest)
71ab6f7e GetProcAddress(WSASetBlockingHook)
71ab6f7e GetProcAddress(WSAUnhookBlockingHook)
71ab6f7e GetProcAddress(WSAGetLastError)
71ab6f7e GetProcAddress(WSASetLastError)
71ab6f7e GetProcAddress(WSACancelBlockingCall)
71ab6f7e GetProcAddress(WSAIsBlocking)
71ab6f7e GetProcAddress(WSAStartup)
71ab6f7e GetProcAddress(WSACleanup)
71ab6f7e GetProcAddress(WSAAccept)
71ab6f7e GetProcAddress(WSACloseEvent)
71ab6f7e GetProcAddress(WSAConnect)
71ab6f7e GetProcAddress(WSACreateEvent)
71ab6f7e GetProcAddress(WSADuplicateSocketA)
71ab6f7e GetProcAddress(WSADuplicateSocketW)
71ab6f7e GetProcAddress(WSAEnumNetworkEvents)
71ab6f7e GetProcAddress(WSAEnumProtocolsA)
71ab6f7e GetProcAddress(WSAEnumProtocolsW)
71ab6f7e GetProcAddress(WSAEventSelect)
71ab6f7e GetProcAddress(WSAGetOverlappedResult)
71ab6f7e GetProcAddress(WSAGetQOSByName)
71ab6f7e GetProcAddress(WSAHtonl)
71ab6f7e GetProcAddress(WSAHtons)
71ab6f7e GetProcAddress(WSAIoctl)
71ab6f7e GetProcAddress(WSAJoinLeaf)
71ab6f7e GetProcAddress(WSANtohl)
71ab6f7e GetProcAddress(WSANtohs)
71ab6f7e GetProcAddress(WSARecv)
71ab6f7e GetProcAddress(WSARecvDisconnect)
71ab6f7e GetProcAddress(WSARecvFrom)
71ab6f7e GetProcAddress(WSAResetEvent)
71ab6f7e GetProcAddress(WSASend)
71ab6f7e GetProcAddress(WSASendDisconnect)
71ab6f7e GetProcAddress(WSASendTo)
71ab6f7e GetProcAddress(WSASetEvent)
71ab6f7e GetProcAddress(WSASocketA)
71ab6f7e GetProcAddress(WSASocketW)
71ab6f7e GetProcAddress(WSAWaitForMultipleEvents)
71ab6f7e GetProcAddress(WSAAddressToStringA)
71ab6f7e GetProcAddress(WSAAddressToStringW)
71ab6f7e GetProcAddress(WSAStringToAddressA)
71ab6f7e GetProcAddress(WSAStringToAddressW)
71ab6f7e GetProcAddress(WSALookupServiceBeginA)
71ab6f7e GetProcAddress(WSALookupServiceBeginW)
71ab6f7e GetProcAddress(WSALookupServiceNextA)
71ab6f7e GetProcAddress(WSALookupServiceNextW)
71ab6f7e GetProcAddress(WSANSPIoctl)
71ab6f7e GetProcAddress(WSALookupServiceEnd)
71ab6f7e GetProcAddress(WSAInstallServiceClassA)
71ab6f7e GetProcAddress(WSAInstallServiceClassW)
71ab6f7e GetProcAddress(WSARemoveServiceClass)
71ab6f7e GetProcAddress(WSAGetServiceClassInfoA)
71ab6f7e GetProcAddress(WSAGetServiceClassInfoW)
71ab6f7e GetProcAddress(WSAEnumNameSpaceProvidersA)
71ab6f7e GetProcAddress(WSAEnumNameSpaceProvidersW)
71ab6f7e GetProcAddress(WSAGetServiceClassNameByClassIdA)
71ab6f7e GetProcAddress(WSAGetServiceClassNameByClassIdW)
71ab6f7e GetProcAddress(WSASetServiceA)
71ab6f7e GetProcAddress(WSASetServiceW)
71ab6f7e GetProcAddress(WSCDeinstallProvider)
71ab6f7e GetProcAddress(WSCInstallProvider)
71ab6f7e GetProcAddress(WSCEnumProtocols)
71ab6f7e GetProcAddress(WSCGetProviderPath)
71ab6f7e GetProcAddress(WSCInstallNameSpace)
71ab6f7e GetProcAddress(WSCUnInstallNameSpace)
71ab6f7e GetProcAddress(WSCEnableNSProvider)
71ab6f7e GetProcAddress(WPUCompleteOverlappedRequest)
71ab6f7e GetProcAddress(WSAProviderConfigChange)
71ab6f7e GetProcAddress(WSCWriteProviderOrder)
71ab6f7e GetProcAddress(WSCWriteNameSpaceOrder)
71ab6f7e GetProcAddress(WSCUpdateProvider)
71ab6f7e GetProcAddress(getaddrinfo)
71ab6f7e GetProcAddress(GetAddrInfoW)
71ab6f7e GetProcAddress(getnameinfo)
71ab6f7e GetProcAddress(GetNameInfoW)
71ab6f7e GetProcAddress(freeaddrinfo)
71ab70df RegOpenKeyExA (HKLM\System\CurrentControlSet\Services\WinSock2\Parameters)
71ab7cc4 RegOpenKeyExA (Protocol_Catalog9)
71ab737e RegOpenKeyExA (00000010)
71ab724d RegOpenKeyExA (Catalog_Entries)
71ab78ea RegOpenKeyExA (000000000001)
71ab78ea RegOpenKeyExA (000000000002)
71ab78ea RegOpenKeyExA (000000000003)
71ab78ea RegOpenKeyExA (000000000004)
71ab78ea RegOpenKeyExA (000000000005)
71ab78ea RegOpenKeyExA (000000000006)
71ab78ea RegOpenKeyExA (000000000007)
71ab78ea RegOpenKeyExA (000000000008)
71ab78ea RegOpenKeyExA (000000000009)
71ab78ea RegOpenKeyExA (000000000010)
71ab78ea RegOpenKeyExA (000000000011)
71ab78ea RegOpenKeyExA (000000000012)
71ab78ea RegOpenKeyExA (000000000013)
71ab78ea RegOpenKeyExA (000000000014)
71ab78ea RegOpenKeyExA (000000000015)
71ab78ea RegOpenKeyExA (000000000016)
71ab78ea RegOpenKeyExA (000000000017)
71ab78ea RegOpenKeyExA (000000000018)
71ab78ea RegOpenKeyExA (000000000019)
71ab78ea RegOpenKeyExA (000000000020)
71ab78ea RegOpenKeyExA (000000000021)
71ab78ea RegOpenKeyExA (000000000022)
71ab78ea RegOpenKeyExA (000000000023)
71ab2623 WaitForSingleObject(778,0)
71ab83c6 RegOpenKeyExA (NameSpace_Catalog5)
71ab737e RegOpenKeyExA (00000004)
71ab7f5b RegOpenKeyExA (Catalog_Entries)
71ab80ef RegOpenKeyExA (000000000001)
71ab80ef RegOpenKeyExA (000000000002)
71ab80ef RegOpenKeyExA (000000000003)
71ab2623 WaitForSingleObject(770,0)
71aa1afa RegOpenKeyExA (HKLM\System\CurrentControlSet\Services\Winsock2\Parameters)
71aa1996 GlobalAlloc()
7c80b689 ExitThread()
7c80b729 GetModuleHandleA((null))
19c07a GetModuleHandleA(kernel32.dll)
19c090 GetProcAddress(VirtualAlloc)
19c0a4 GetProcAddress(VirtualFree)
19c4ac GetModuleHandleA(kernel32.dll)
19c513 GetProcAddress(GetCurrentThreadId)
19c513 GetProcAddress(DeleteCriticalSection)
19c513 GetProcAddress(LeaveCriticalSection)
19c513 GetProcAddress(EnterCriticalSection)
19c513 GetProcAddress(InitializeCriticalSection)
19c513 GetProcAddress(VirtualFree)
19c513 GetProcAddress(VirtualAlloc)
19c513 GetProcAddress(LocalFree)
19c513 GetProcAddress(LocalAlloc)
19c513 GetProcAddress(VirtualQuery)
19c513 GetProcAddress(WideCharToMultiByte)
19c513 GetProcAddress(MultiByteToWideChar)
19c513 GetProcAddress(lstrlenA)
19c513 GetProcAddress(lstrcpyA)
19c513 GetProcAddress(LoadLibraryExA)
19c513 GetProcAddress(GetThreadLocale)
19c513 GetProcAddress(GetStartupInfoA)
19c513 GetProcAddress(GetModuleFileNameA)
19c513 GetProcAddress(GetLocaleInfoA)
19c513 GetProcAddress(GetLastError)
19c513 GetProcAddress(GetCommandLineA)
19c513 GetProcAddress(FreeLibrary)
19c513 GetProcAddress(ExitProcess)
19c513 GetProcAddress(WriteFile)
19c513 GetProcAddress(SetFilePointer)
19c513 GetProcAddress(SetEndOfFile)
19c513 GetProcAddress(RtlUnwind)
19c513 GetProcAddress(ReadFile)
19c513 GetProcAddress(RaiseException)
19c513 GetProcAddress(GetStdHandle)
19c513 GetProcAddress(GetFileSize)
19c513 GetProcAddress(GetSystemTime)
19c513 GetProcAddress(GetFileType)
19c513 GetProcAddress(CreateFileA)
19c513 GetProcAddress(CloseHandle)
19c4ac GetModuleHandleA(user32.dll)
19c513 GetProcAddress(GetKeyboardType)
19c513 GetProcAddress(LoadStringA)
19c513 GetProcAddress(MessageBoxA)
19c4ac GetModuleHandleA(advapi32.dll)
19c513 GetProcAddress(RegQueryValueExA)
19c513 GetProcAddress(RegOpenKeyExA)
19c513 GetProcAddress(RegCloseKey)
19c4ac GetModuleHandleA(oleaut32.dll)
19c513 GetProcAddress(VariantChangeTypeEx)
19c513 GetProcAddress(VariantCopyInd)
19c513 GetProcAddress(VariantClear)
19c513 GetProcAddress(SysStringLen)
19c513 GetProcAddress(SysFreeString)
19c513 GetProcAddress(SysAllocStringLen)
19c4ac GetModuleHandleA(kernel32.dll)
19c513 GetProcAddress(TlsSetValue)
19c513 GetProcAddress(TlsGetValue)
19c513 GetProcAddress(TlsFree)
19c513 GetProcAddress(TlsAlloc)
19c513 GetProcAddress(LocalFree)
19c513 GetProcAddress(LocalAlloc)
19c513 GetProcAddress(GetModuleFileNameA)
19c4ac GetModuleHandleA(advapi32.dll)
19c513 GetProcAddress(RegSetValueExA)
19c513 GetProcAddress(RegSetValueA)
19c513 GetProcAddress(RegQueryValueExA)
19c513 GetProcAddress(RegQueryInfoKeyA)
19c513 GetProcAddress(RegOpenKeyExA)
19c513 GetProcAddress(RegEnumKeyExA)
19c513 GetProcAddress(RegCloseKey)
19c4ac GetModuleHandleA(kernel32.dll)
19c513 GetProcAddress(VirtualQuery)
19c513 GetProcAddress(UnmapViewOfFile)
19c513 GetProcAddress(UnhandledExceptionFilter)
19c513 GetProcAddress(MapViewOfFile)
19c513 GetProcAddress(LockResource)
19c513 GetProcAddress(LoadResource)
19c513 GetProcAddress(GlobalFree)
19c513 GetProcAddress(GlobalAlloc)
19c513 GetProcAddress(GetVolumeInformationA)
19c513 GetProcAddress(GetVersionExA)
19c513 GetProcAddress(GetVersion)
19c513 GetProcAddress(GetThreadLocale)
19c513 GetProcAddress(GetProcAddress)
19c513 GetProcAddress(GetModuleHandleA)
19c513 GetProcAddress(GetModuleFileNameA)
19c513 GetProcAddress(GetLocaleInfoA)
19c513 GetProcAddress(GetLocalTime)
19c513 GetProcAddress(GetDriveTypeA)
19c513 GetProcAddress(GetDiskFreeSpaceA)
19c513 GetProcAddress(GetCurrentProcessId)
19c513 GetProcAddress(GetCurrentProcess)
19c513 GetProcAddress(GetCommandLineA)
19c513 GetProcAddress(GetCPInfo)
19c513 GetProcAddress(FindResourceA)
19c513 GetProcAddress(ExitProcess)
19c513 GetProcAddress(EnumCalendarInfoA)
19c513 GetProcAddress(CreateFileMappingA)
19c513 GetProcAddress(CreateFileA)
19c513 GetProcAddress(CloseHandle)
19c4ac GetModuleHandleA(user32.dll)
19c513 GetProcAddress(MessageBoxA)
19c513 GetProcAddress(LoadStringA)
19c513 GetProcAddress(GetSystemMetrics)
19c513 GetProcAddress(FindWindowA)
19c513 GetProcAddress(DialogBoxIndirectParamA)
19c4ac GetModuleHandleA(ole32.dll)
19c513 GetProcAddress(CoCreateGuid)
184063 RegOpenKeyExA (HKCU\Software\Borland\Locales)
184081 RegOpenKeyExA (HKCU\Software\Borland\Delphi\Locales)
184e9d GetCommandLineA()
5ad8ef89 GetCurrentProcessId()=3964
5ad7b1ba IsDebuggerPresent()
187eb7 GetVersionExA()
18846f GetModuleHandleA(kernel32.dll)
188480 GetProcAddress(GetDiskFreeSpaceExA)
182667 GetSystemTime()
191a43 GetModuleHandleA((null))
191a7d GetVersionExA()
191aac GetCurrentProcessId()=3964
191ac8 GetCommandLineA()
191674 GetModuleHandleA(kernel32.dll)
191692 GetProcAddress(IsDebuggerPresent)
19169c IsDebuggerPresent()
191247 GlobalAlloc()
191275 GetModuleHandleA(ntdll.dll)
191299 GetProcAddress(NtQuerySystemInformation)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(DeleteCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LeaveCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(EnterCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(InitializeCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(VirtualFree)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(VirtualAlloc)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LocalFree)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LocalAlloc)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetTickCount)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(QueryPerformanceCounter)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetCurrentThreadId)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(InterlockedDecrement)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(InterlockedIncrement)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(VirtualQuery)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(WideCharToMultiByte)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(MultiByteToWideChar)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(lstrlenA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(lstrcpynA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LoadLibraryExA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetThreadLocale)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetStartupInfoA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetModuleFileNameA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetLocaleInfoA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetLastError)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FreeLibrary)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FindFirstFileA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FindClose)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(ExitProcess)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(WriteFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(UnhandledExceptionFilter)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetFilePointer)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetEndOfFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(RtlUnwind)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(ReadFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(RaiseException)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetStdHandle)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetFileSize)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetFileType)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CreateFileA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CloseHandle)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetKeyboardType)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(LoadStringA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(MessageBoxA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CharNextA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegQueryValueExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegOpenKeyExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegCloseKey)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SysFreeString)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SysReAllocStringLen)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SysAllocStringLen)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(TlsSetValue)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(TlsGetValue)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LocalAlloc)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegSetValueExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegQueryValueExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegQueryInfoKeyA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegOpenKeyExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegFlushKey)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegEnumValueA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegEnumKeyExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegDeleteValueA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegDeleteKeyA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegCreateKeyExA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(RegCloseKey)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(OpenProcessToken)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(LookupPrivilegeValueA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(AdjustTokenPrivileges)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(lstrcpyA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(WriteFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(WaitForSingleObject)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(VirtualQuery)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(VirtualAlloc)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(UnmapViewOfFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(TerminateProcess)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(Sleep)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SizeofResource)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetThreadLocale)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetFileTime)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetFilePointer)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetFileAttributesA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetEvent)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetErrorMode)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SetEndOfFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(SearchPathA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(ResetEvent)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(RemoveDirectoryA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(ReadFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(OpenProcess)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(MultiByteToWideChar)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(MulDiv)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(MoveFileExA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(MapViewOfFile)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LocalFileTimeToFileTime)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LoadResource)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LoadLibraryA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(LeaveCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(InitializeCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalUnlock)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalReAlloc)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalHandle)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalLock)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalFree)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalFindAtomA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalDeleteAtom)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalAlloc)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GlobalAddAtomA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetWindowsDirectoryA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetVolumeInformationA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetVersionExA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetTickCount)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetThreadLocale)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetSystemInfo)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetSystemDirectoryA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetStringTypeExA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetStdHandle)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetShortPathNameA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetModuleFileNameA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetLocaleInfoA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetLocalTime)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetLastError)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetFullPathNameA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetFileSize)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetFileAttributesA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetExitCodeProcess)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetEnvironmentVariableA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetDriveTypeA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetDiskFreeSpaceA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetDateFormatA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetCurrentThreadId)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetComputerNameA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetCPInfo)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(GetACP)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(InterlockedExchange)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FreeLibrary)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FormatMessageA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FindResourceA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FindNextFileA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FindFirstFileA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FindClose)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FileTimeToLocalFileTime)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(FileTimeToDosDateTime)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(ExpandEnvironmentStringsA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(EnumCalendarInfoA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(EnterCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(DosDateTimeToFileTime)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(DeleteFileA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(DeleteCriticalSection)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CreateThread)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CreateProcessA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CreateFileMappingA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CreateFileA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CreateEventA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CompareStringA)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(CloseHandle)
192f29 GetModuleHandleA(version.dll)
192f39 GetProcAddress(VerQueryValueA)
192f29 GetModuleHandleA(version.dll)
192f39 GetProcAddress(GetFileVersionInfoSizeA)
192f29 GetModuleHandleA(version.dll)
192f39 GetProcAddress(GetFileVersionInfoA)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(UnrealizeObject)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(StretchBlt)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetWindowOrgEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetWinMetaFileBits)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetViewportOrgEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetTextColor)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetStretchBltMode)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetROP2)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetPixel)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetEnhMetaFileBits)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetDIBColorTable)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetBrushOrgEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetBkMode)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SetBkColor)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SelectPalette)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SelectObject)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(SaveDC)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(RoundRect)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(RestoreDC)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(Rectangle)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(RectVisible)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(RealizePalette)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(Polyline)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(PlayEnhMetaFile)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(PatBlt)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(MoveToEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(MaskBlt)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(LineTo)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(IntersectClipRect)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetWindowOrgEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetWinMetaFileBits)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetTextMetricsA)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetTextExtentPointA)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetTextExtentPoint32A)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetSystemPaletteEntries)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetStockObject)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetPixel)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetPaletteEntries)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetObjectA)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetEnhMetaFilePaletteEntries)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetEnhMetaFileHeader)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetEnhMetaFileBits)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetDeviceCaps)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetDIBits)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetDIBColorTable)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetDCOrgEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetCurrentPositionEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetClipBox)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetBrushOrgEx)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(GetBitmapBits)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(ExcludeClipRect)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(Ellipse)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(DeleteObject)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(DeleteEnhMetaFile)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(DeleteDC)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateSolidBrush)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreatePenIndirect)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreatePalette)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateHalftonePalette)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateFontIndirectA)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateDIBitmap)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateDIBSection)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateCompatibleDC)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateCompatibleBitmap)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateBrushIndirect)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CreateBitmap)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(CopyEnhMetaFileA)
192f29 GetModuleHandleA(gdi32.dll)
192f39 GetProcAddress(BitBlt)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CreateWindowExA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(WindowFromPoint)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(WinHelpA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(WaitMessage)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(UpdateWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(UnregisterClassA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(UnhookWindowsHookEx)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(TranslateMessage)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(TranslateMDISysAccel)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(TrackPopupMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SystemParametersInfoA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ShowWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ShowScrollBar)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ShowOwnedPopups)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ShowCursor)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetWindowsHookExA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetWindowTextA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetWindowPos)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetWindowPlacement)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetWindowLongA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetTimer)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetScrollRange)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetScrollPos)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetScrollInfo)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetPropA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetParent)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetMenuItemInfoA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetForegroundWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetFocus)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetCursor)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetClipboardData)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetClassLongA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetCapture)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SetActiveWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(SendMessageA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ScrollWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ScreenToClient)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(RemovePropA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(RemoveMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ReleaseDC)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ReleaseCapture)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(RegisterWindowMessageA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(RegisterClipboardFormatA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(RegisterClassA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(RedrawWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(PtInRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(PostQuitMessage)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(PostMessageA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(PeekMessageA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(OpenClipboard)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(OffsetRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(OemToCharA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(MessageBoxA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(MessageBeep)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(MapWindowPoints)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(MapVirtualKeyA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(LoadStringA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(LoadKeyboardLayoutA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(LoadIconA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(LoadCursorA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(LoadBitmapA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(KillTimer)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsZoomed)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsWindowVisible)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsWindowEnabled)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsRectEmpty)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsIconic)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsDialogMessageA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IsChild)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(InvalidateRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(IntersectRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(InsertMenuItemA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(InsertMenuA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(InflateRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowThreadProcessId)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowTextA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowPlacement)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowModuleFileNameA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowLongA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindowDC)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetTopWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetSystemMetrics)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetSystemMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetSysColorBrush)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetSysColor)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetSubMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetScrollRange)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetScrollPos)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetScrollInfo)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetPropA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetParent)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetMenuStringA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetMenuState)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetMenuItemInfoA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetMenuItemID)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetMenuItemCount)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetLastActivePopup)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetKeyboardState)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetKeyboardLayoutList)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetKeyboardLayout)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetKeyState)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetKeyNameTextA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetIconInfo)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetForegroundWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetFocus)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetDesktopWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetDCEx)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetDC)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetCursorPos)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetCursor)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetClipboardData)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetClientRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetClassNameA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetClassInfoA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetCapture)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(GetActiveWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(FrameRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(FindWindowA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(FillRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ExitWindowsEx)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EqualRect)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EnumWindows)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EnumThreadWindows)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EndPaint)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EnableWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EnableScrollBar)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EnableMenuItem)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(EmptyClipboard)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DrawTextA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DrawMenuBar)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DrawIconEx)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DrawIcon)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DrawFrameControl)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DrawEdge)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DispatchMessageA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DestroyWindow)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DestroyMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DestroyIcon)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DestroyCursor)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DeleteMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DefWindowProcA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DefMDIChildProcA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(DefFrameProcA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CreatePopupMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CreateMenu)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CreateIcon)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CloseClipboard)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ClientToScreen)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CheckMenuItem)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CallWindowProcA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CallNextHookEx)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(BeginPaint)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CharNextA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CharLowerBuffA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CharLowerA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CharUpperBuffA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(CharToOemA)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(AdjustWindowRectEx)
192f29 GetModuleHandleA(user32.dll)
192f39 GetProcAddress(ActivateKeyboardLayout)
192f29 GetModuleHandleA(kernel32.dll)
192f39 GetProcAddress(Sleep)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SafeArrayPtrOfIndex)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SafeArrayGetUBound)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SafeArrayGetLBound)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SafeArrayCreate)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(VariantChangeType)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(VariantCopy)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(VariantClear)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(VariantInit)
192f29 GetModuleHandleA(ole32.dll)
192f39 GetProcAddress(CoUninitialize)
192f29 GetModuleHandleA(ole32.dll)
192f39 GetProcAddress(CoInitialize)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(GetErrorInfo)
192f29 GetModuleHandleA(oleaut32.dll)
192f39 GetProcAddress(SysFreeString)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_SetIconSize)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_GetIconSize)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Write)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Read)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_GetDragImage)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_DragShowNolock)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_SetDragCursorImage)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_DragMove)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_DragLeave)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_DragEnter)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_EndDrag)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_BeginDrag)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Remove)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_DrawEx)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Draw)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_GetBkColor)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_SetBkColor)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_ReplaceIcon)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Add)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_GetImageCount)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Destroy)
192f29 GetModuleHandleA(comctl32.dll)
192f39 GetProcAddress(ImageList_Create)
192f29 GetModuleHandleA(shell32.dll)
192f39 GetProcAddress(ShellExecuteA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetSetOptionA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetReadFile)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetQueryOptionA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetOpenUrlA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetOpenA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetErrorDlg)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetConnectA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(InternetCloseHandle)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(HttpSendRequestA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(HttpQueryInfoA)
192f29 GetModuleHandleA(wininet.dll)
192f39 GetProcAddress(HttpOpenRequestA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(QueryServiceStatus)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(OpenServiceA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(OpenSCManagerA)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(DeleteService)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(ControlService)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(CloseServiceHandle)
192f29 GetModuleHandleA(advapi32.dll)
192f39 GetProcAddress(ChangeServiceConfigA)
191fae CreateFileA(\\.\SICE)
191fae CreateFileA(\\.\NTICE)
191fae CreateFileA(\\.\SIWVID)
189575 RegSetValueA (HKCR\.key,)
77e0723f RegCreateKeyExA (.key,(null))
77de6fb8 RegSetValueExA ((null))
1895ac RegOpenKeyExA (HKCR\.key)
1895d6 RegSetValueExA ()
191cdf GetModuleHandleA((null))
406077 RegOpenKeyExA (HKCU\Software\Borland\Locales)
406095 RegOpenKeyExA (HKLM\Software\Borland\Locales)
4060b3 RegOpenKeyExA (HKCU\Software\Borland\Delphi\Locales)
40d267 GetVersionExA()
191c87 GetModuleHandleA(kernel32.dll)
1917c9 GetProcAddress(GetDiskFreeSpaceExA)
191c87 GetModuleHandleA(oleaut32.dll)
1917c9 GetProcAddress(VariantChangeTypeEx)
1917c9 GetProcAddress(VarNeg)
1917c9 GetProcAddress(VarNot)
1917c9 GetProcAddress(VarAdd)
1917c9 GetProcAddress(VarSub)
1917c9 GetProcAddress(VarMul)
1917c9 GetProcAddress(VarDiv)
1917c9 GetProcAddress(VarIdiv)
1917c9 GetProcAddress(VarMod)
1917c9 GetProcAddress(VarAnd)
1917c9 GetProcAddress(VarOr)
1917c9 GetProcAddress(VarXor)
1917c9 GetProcAddress(VarCmp)
1917c9 GetProcAddress(VarI4FromStr)
1917c9 GetProcAddress(VarR4FromStr)
1917c9 GetProcAddress(VarR8FromStr)
1917c9 GetProcAddress(VarDateFromStr)
1917c9 GetProcAddress(VarCyFromStr)
1917c9 GetProcAddress(VarBoolFromStr)
1917c9 GetProcAddress(VarBstrFromCy)
1917c9 GetProcAddress(VarBstrFromDate)
1917c9 GetProcAddress(VarBstrFromBool)
191c87 GetModuleHandleA(USER32.DLL)
1917c9 GetProcAddress(GetMonitorInfoA)
1917c9 GetProcAddress(GetSystemMetrics)
1917c9 GetProcAddress(EnumDisplayMonitors)
74723bee GetModuleHandleA(C:\WINDOWS\system32\ntdll.dll)
74723b62 GetProcAddress(NtQueryInformationProcess)
747226aa GetVersionExA()
74723bee GetModuleHandleA(C:\WINDOWS\system32\imm32.dll)
7472279f GetProcAddress(CtfImmCoUninitialize)
747227dc GetProcAddress(CtfImmLastEnabledWndDestroy)
7472281f GetProcAddress(CtfImmSetCiceroStartInThread)
74722864 GetProcAddress(CtfImmIsCiceroStartedInThread)
747228a9 GetProcAddress(CtfImmIsCiceroEnabled)
747228e5 GetProcAddress(CtfImmIsTextFrameServiceDisabled)
7472292c GetProcAddress(CtfImmEnterCoInitCountSkipMode)
74722972 GetProcAddress(CtfImmLeaveCoInitCountSkipMode)
747229b6 GetProcAddress(ImmGetDefaultIMEWnd)
747229ef GetProcAddress(ImmReleaseContext)
74722a29 GetProcAddress(ImmNotifyIME)
74722a5c GetProcAddress(ImmSetConversionStatus)
74722a9a GetProcAddress(ImmGetConversionStatus)
74722ad6 GetProcAddress(ImmGetProperty)
74722b0a GetProcAddress(ImmGetOpenStatus)
74722b40 GetProcAddress(ImmGetContext)
74722b75 GetProcAddress(ImmSetOpenStatus)
74722bac GetProcAddress(ImmInstallIMEA)
74722be2 GetProcAddress(ImmGetDescriptionA)
74722c1a GetProcAddress(ImmGetDescriptionW)
74722c52 GetProcAddress(ImmGetIMEFileNameA)
74722c8a GetProcAddress(ImmGetIMEFileNameW)
74723168 GetProcAddress(ImmSetHotKey)
747230a7 RegOpenKeyExA (HKLM\SOFTWARE\Microsoft\CTF\Compatibility\xclean_micro.exe)
747230a7 RegOpenKeyExA (HKLM\SOFTWARE\Microsoft\CTF\SystemShared\)
7472245b CreateMutex(CTF.LBES.MutexDefaultS-1-5-21-823518204-776561741-839522115-1003)
7472245b CreateMutex(CTF.Compart.MutexDefaultS-1-5-21-823518204-776561741-839522115-1003)
7472245b CreateMutex(CTF.Asm.MutexDefaultS-1-5-21-823518204-776561741-839522115-1003)
7472245b CreateMutex(CTF.Layouts.MutexDefaultS-1-5-21-823518204-776561741-839522115-1003)
7472245b CreateMutex(CTF.TMD.MutexDefaultS-1-5-21-823518204-776561741-839522115-1003)
747230a7 RegOpenKeyExA (HKCU\Keyboard Layout\Toggle)
747226aa GetVersionExA()
74723bee GetModuleHandleA(C:\WINDOWS\system32\KERNEL32)
74722d2b GetProcAddress(GetUserDefaultUILanguage)
7472260a RegOpenKeyExA (HKLM\SOFTWARE\Microsoft\CTF\)
74724683 GetCurrentProcessId()=3964
7472245b CreateMutex(CTF.TimListCache.FMPDefaultS-1-5-21-823518204-776561741-839522115-1003MUTEX.DefaultS-1-5-21-823518204-776561741-839522115-1003)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7475556a GetCurrentProcessId()=3964
7473d232 WaitForSingleObject(740,1388)
763985f8 GetProcAddress(GetFileVersionInfoW)
7639860d GetProcAddress(GetFileVersionInfoSizeW)
76398622 GetProcAddress(VerQueryValueW)
7c816513 WaitForSingleObject(738,64)
755d8f33 GetVersionExA()
755e5225 GetVersionExA()
755dd4f4 LoadLibraryA(C:\WINDOWS\system32\ole32.dll)=774e0000
755da32e GetProcAddress(CoCreateInstance)
763a3b62 GetProcAddress(CtfImeCreateThreadMgr)
763a3b7c GetProcAddress(CtfImeDestroyThreadMgr)
763a3b96 GetProcAddress(CtfImeCreateInputContext)
763a3bac GetProcAddress(CtfImeDestroyInputContext)
763a3bc2 GetProcAddress(CtfImeSetActiveContextAlways)
763a3bd8 GetProcAddress(CtfImeProcessCicHotkey)
763a3bee GetProcAddress(CtfImeDispatchDefImeMessage)
763a3c04 GetProcAddress(CtfImeIsIME)
755dd4a4 GetModuleHandleA(C:\WINDOWS\system32\ntdll.dll)
755d8acc GetProcAddress(RtlDllShutdownInProgress)
7c816513 WaitForSingleObject(738,64)
7639722d GetProcAddress(ImeInquire)
76397242 GetProcAddress(ImeConversionList)
76397257 GetProcAddress(ImeRegisterWord)
7639726c GetProcAddress(ImeUnregisterWord)
76397281 GetProcAddress(ImeGetRegisterWordStyle)
76397296 GetProcAddress(ImeEnumRegisterWord)
763972ab GetProcAddress(ImeConfigure)
763972c0 GetProcAddress(ImeDestroy)
763972d5 GetProcAddress(ImeEscape)
763972ea GetProcAddress(ImeProcessKey)
763972ff GetProcAddress(ImeSelect)
76397314 GetProcAddress(ImeSetActiveContext)
7639732c GetProcAddress(ImeToAsciiEx)
76397344 GetProcAddress(NotifyIME)
7639735c GetProcAddress(ImeSetCompositionString)
76397374 GetProcAddress(ImeGetImeMenuItems)
763973b4 GetProcAddress(CtfImeInquireExW)
763973c8 GetProcAddress(CtfImeSelectEx)
763973dc GetProcAddress(CtfImeEscapeEx)
763973f0 GetProcAddress(CtfImeGetGuidAtom)
76397404 GetProcAddress(CtfImeIsGuidMapEnable)
191c87 GetModuleHandleA(USER32)
1917c9 GetProcAddress(AnimateWindow)
191c87 GetModuleHandleA(comctl32.dll)
1917c9 GetProcAddress(InitializeFlatSB)
1917c9 GetProcAddress(UninitializeFlatSB)
1917c9 GetProcAddress(FlatSB_GetScrollProp)
1917c9 GetProcAddress(FlatSB_SetScrollProp)
1917c9 GetProcAddress(FlatSB_EnableScrollBar)
1917c9 GetProcAddress(FlatSB_ShowScrollBar)
1917c9 GetProcAddress(FlatSB_GetScrollRange)
1917c9 GetProcAddress(FlatSB_GetScrollInfo)
1917c9 GetProcAddress(FlatSB_GetScrollPos)
1917c9 GetProcAddress(FlatSB_SetScrollPos)
1917c9 GetProcAddress(FlatSB_SetScrollInfo)
1917c9 GetProcAddress(FlatSB_SetScrollRange)
191c87 GetModuleHandleA(User32.dll)
1917c9 GetProcAddress(SetLayeredWindowAttributes)
191c87 GetModuleHandleA(ole32.dll)
1917c9 GetProcAddress(CoCreateInstanceEx)
1917c9 GetProcAddress(CoInitializeEx)
1917c9 GetProcAddress(CoAddRefServerProcess)
1917c9 GetProcAddress(CoReleaseServerProcess)
1917c9 GetProcAddress(CoResumeClassObjects)
1917c9 GetProcAddress(CoSuspendClassObjects)
191c87 GetModuleHandleA(kernel32.dll)
465284 LoadLibraryA(shell32.dll)=7c9c0000
1917c9 GetProcAddress(SHEmptyRecycleBinA)
4652b1 LoadLibraryA(user32.dll)=7e410000
1917c9 GetProcAddress(GetWindowModuleFileNameA)
42ecf1 RegOpenKeyExA (HKCU\Software\X-Cleaner)
403448 CreateFileA(C:\UBCD4Win\306-test\plugin\AntiSpyware\XBlock\xclean_micro.exe)
402f19 ReadFile()
42ecf1 RegOpenKeyExA (HKCU\Software\X-Cleaner)
1917c9 GetProcAddress(MonitorFromWindow)
773d3f9f LoadLibraryA(UxTheme.dll)=5ad70000
773d4000 GetProcAddress(EnableThemeDialogTexture)
773d4000 GetProcAddress(OpenThemeData)
7473d232 WaitForSingleObject(74c,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(754,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
773d4000 GetProcAddress(IsThemeBackgroundPartiallyTransparent)
773d4000 GetProcAddress(DrawThemeParentBackground)
773ea491 GetCurrentProcessId()=3964
773d4000 GetProcAddress(DrawThemeBackground)
773ea491 GetCurrentProcessId()=3964
773d4000 GetProcAddress(GetThemeBackgroundContentRect)
773d4000 GetProcAddress(DrawThemeText)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
747230a7 RegOpenKeyExA (HKCU\Keyboard Layout\Toggle)
7473d232 WaitForSingleObject(754,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(754,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(754,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
747230a7 RegOpenKeyExA (HKCU\SOFTWARE\Microsoft\CTF\LangBarAddIn\)
747230a7 RegOpenKeyExA (HKLM\SOFTWARE\Microsoft\CTF\LangBarAddIn\)
7473d232 WaitForSingleObject(754,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7472245b CreateMutex(MSCTF.Shared.MUTEX.ABF)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
74723bee GetModuleHandleA(C:\WINDOWS\system32\ntdll.dll)
7475ee00 GetProcAddress(RtlDllShutdownInProgress)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7473d232 WaitForSingleObject(72c,1388)
7c341e17 GetVersionExA()
7c341897 GetModuleHandleA(kernel32.dll)
7c3418ab GetProcAddress(InitializeCriticalSectionAndSpinCount)
7c34193c GetModuleHandleA(kernel32.dll)
7c341950 GetProcAddress(FlsAlloc)
7c34195d GetProcAddress(FlsGetValue)
7c34196a GetProcAddress(FlsSetValue)
7c341977 GetProcAddress(FlsFree)
7c341e95 GetCommandLineA()
7c341fc6 GetModuleHandleA(KERNEL32)
7c341fda GetProcAddress(IsProcessorFeaturePresent)
773d4000 GetProcAddress(HitTestThemeBackground)
773ea491 GetCurrentProcessId()=3964
773ea491 GetCurrentProcessId()=3964
773ea491 GetCurrentProcessId()=3964
773ea491 GetCurrentProcessId()=3964
773ea491 GetCurrentProcessId()=3964
7473d232 WaitForSingleObject(740,1388)
7473d232 WaitForSingleObject(740,1388)
773d4000 GetProcAddress(CloseThemeData)
407873 GlobalAlloc()
42a74b LoadLibraryA(uxtheme.dll)=5ad70000
1917c9 GetProcAddress(OpenThemeData)
1917c9 GetProcAddress(CloseThemeData)
1917c9 GetProcAddress(DrawThemeBackground)
1917c9 GetProcAddress(DrawThemeText)
1917c9 GetProcAddress(GetThemeBackgroundContentRect)
1917c9 GetProcAddress(GetThemeBackgroundContentRect)
1917c9 GetProcAddress(GetThemePartSize)
1917c9 GetProcAddress(GetThemeTextExtent)
1917c9 GetProcAddress(GetThemeTextMetrics)
1917c9 GetProcAddress(GetThemeBackgroundRegion)
1917c9 GetProcAddress(HitTestThemeBackground)
1917c9 GetProcAddress(DrawThemeEdge)
1917c9 GetProcAddress(DrawThemeIcon)
1917c9 GetProcAddress(IsThemePartDefined)
1917c9 GetProcAddress(IsThemeBackgroundPartiallyTransparent)
1917c9 GetProcAddress(GetThemeColor)
1917c9 GetProcAddress(GetThemeMetric)
1917c9 GetProcAddress(GetThemeString)
1917c9 GetProcAddress(GetThemeBool)
1917c9 GetProcAddress(GetThemeInt)
1917c9 GetProcAddress(GetThemeEnumValue)
1917c9 GetProcAddress(GetThemePosition)
1917c9 GetProcAddress(GetThemeFont)
1917c9 GetProcAddress(GetThemeRect)
1917c9 GetProcAddress(GetThemeMargins)
1917c9 GetProcAddress(GetThemeIntList)
1917c9 GetProcAddress(GetThemePropertyOrigin)
1917c9 GetProcAddress(SetWindowTheme)
1917c9 GetProcAddress(GetThemeFilename)
1917c9 GetProcAddress(GetThemeSysColor)
1917c9 GetProcAddress(GetThemeSysColorBrush)
1917c9 GetProcAddress(GetThemeSysBool)
1917c9 GetProcAddress(GetThemeSysSize)
1917c9 GetProcAddress(GetThemeSysFont)
1917c9 GetProcAddress(GetThemeSysString)
1917c9 GetProcAddress(GetThemeSysInt)
1917c9 GetProcAddress(IsThemeActive)
1917c9 GetProcAddress(IsAppThemed)
1917c9 GetProcAddress(GetWindowTheme)
1917c9 GetProcAddress(EnableThemeDialogTexture)
1917c9 GetProcAddress(IsThemeDialogTextureEnabled)
1917c9 GetProcAddress(GetThemeAppProperties)
1917c9 GetProcAddress(SetThemeAppProperties)
1917c9 GetProcAddress(GetCurrentThemeName)
1917c9 GetProcAddress(GetThemeDocumentationProperty)
1917c9 GetProcAddress(DrawThemeParentBackground)
1917c9 GetProcAddress(EnableTheming)
7473d232 WaitForSingleObject(740,1388)
7473d91c OpenProcess(pid=1572)
7472245b CreateMutex(MSCTF.Shared.MUTEX.EJI)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(740,1388)
7473f824 WaitForSingleObject(720,0)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(740,1388)
7473f824 WaitForSingleObject(720,0)
7473d232 WaitForSingleObject(71c,1388)
7473d232 WaitForSingleObject(71c,1388)
42f50c RegOpenKeyExA (HKLM\SOFTWARE\Ernst & Young\Loadset)
40494b ExitProcess()
755d9a75 GetProcAddress(TF_DllDetachInOther)
74721d36 GetCurrentProcessId()=3964
74722056 GetCurrentProcessId()=3964
74724683 GetCurrentProcessId()=3964
7475556a GetCurrentProcessId()=3964
5ad7adb2 GetCurrentProcessId()=3964
***** Injected Process Terminated *****
7ca26a01 GetCurrentProcessId()=3964
7ca2aa8b GetProcAddress(ReleaseActCtx)
7745b606 GetProcAddress(ReleaseActCtx)
I see nothing malicious...
If you're afraid of taking any chances then the chances are great that you will never learn anything
Multiboot Plugins - UBUSB (Ultimate Boot USB) - EzPcFix - RootKitty - Network Configuration Utility - UnIsoFS - A Small Linux Distro - SELogger - HashME - WSock - My Paypal
Multiboot Plugins - UBUSB (Ultimate Boot USB) - EzPcFix - RootKitty - Network Configuration Utility - UnIsoFS - A Small Linux Distro - SELogger - HashME - WSock - My Paypal
Page 1 of 1

Sign In
Register
Help

MultiQuote

