Help - Search - Members - Calendar
Full Version: Got Trojan Warning from Norton Anitvirus during install
UBCD4Win Forums > Main Forum: UBCD4Windows - Support > AntiVirus False positives and Hash Check problems
ATO_UBCD
Dear Everyone!

Trying to help a family member with a "crashed disk" thought UBCD could be very useful, however after downloading (the Mirror from ZD Net, download on October 19th), when I tried to "install" I got a warning regarding the file:

plugin\AntiSpyware\XBlock\xclean_micro.exe, 09B550B74C729232F2C88A9B98AE4F0C
(My Norton also blocked the Hash sum test, but avter Trojan warning I was a bit worried anyway )

And My Norton Antivirus package informs me that there is a Trojan called: Trojan.Zlob.N that gets installed (thus this file gets removed by Norton)

I paste in some "Message winwos below", sorry for the Norwegian language.

Thanks beforehand for any suggestions - hints
kind regards
ATO/Arnfinn (from Norway)

***********


Trojan Detected in UBCD4WIN olugi is-09ETL.tmp

Trojan.Zlob.N

plugin\AntiSpyware\XBlock\xclean_micro.exe, 09B550B74C729232F2C88A9B98AE4F0C has been removed.


The listing on that particular Troja is as follows:

**********
Discovered: May 8, 2007
Updated: May 8, 2007 4:56:19 PM
Type: Trojan
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

When the Trojan is executed, it installs the following toolbar in Internet Explorer:
Protection Bar



The Trojan then creates the following files:

* %CurrentFolder%\smmain.exe
* %CurrentFolder%\smmon.exe
* %CurrentFolder%\splug.dll
* %CurrentFolder%\spunst.exe
* %CurrentFolder%\smunst.exe
* %CurrentFolder%\spunst.exe



It may also drop the following file:
%ProgramFiles%\Video ActiveX Access\iesmin.exe

Next, the Trojan creates the following registry entry so that it executes whenever Windows starts:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\"rare" = "%CurrentFolder%\smmain.exe"

It also creates the following registry entry:
HKEY_CURRENT_USER\Software\Protection Tools\"65005" = "1"

The Trojan also creates the following registry subkeys:
HKEY_CLASSES_ROOT\CLSID\{F0993251-2512-4710-AF6E-0A13EA199D02}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{F0993251-2512-4710-AF6E-0A13EA199D02}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F0993251-2512-4710-AF6E-0A13EA199D02}
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{F0993251-2512-4710-AF6E-0A13EA199D02}
rdsok
Please read the FAQ's see http://www.ubcd4win.com/faq.htm#false

As proof... see Softpedia's info here http://www.softpedia.com/progClean/UBCD4WIN-Clean-76994.html


Please report the false positive to Norton... if they won't correct the issue... consider using a product that the company will respond to their users complaints
pcuser
Here's the results from running the suspect file through SysAnalyzer

CODE
File: xclean_micro.exe
Size: 750616 Bytes
MD5: 09B550B74C729232F2C88A9B98AE4F0C
Packer: File not found C:\iDEFENSE\SysAnalyzer\peid.exe

File Properties: CompanyName      XBlock.com
FileDescription  X-Cleaner
FileVersion      1.1.1.11
InternalName     InternalName
LegalCopyright   (C) 2003 by X-Block.com
OriginalFilename OriginalFileName
ProductName      ProductName
ProductVersion  

Exploit Signatures:
---------------------------------------------------------------------------
Scanning for 19 signatures
Scan Complete: 1896Kb in 0.094 seconds
Urls
--------------------------------------------------
IEZON|http://*.systemdoctor.com
IEZON| http://www.winantivirus.com
IEZON| http://www.winantiviruspro.com
Please use the update feature or visit http://www.xblock.com/ to receive the needed updates.(This program will stop functioning soon!

RegKeys
--------------------------------------------------
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , *.system-processes
REGKE|HKEY_CURRENT_USER\Software\Maxthon\Plugin\toolbar\{44BE0690-5429-47f0-85BB-3FFD8020233E}
REGKE|HKEY_CURRENT_USER\Software\VoiceIP
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\webHancer Agent
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WUSE.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WUSN.1
NEWPR|2337|WhistleSoftware
DIREC|%ProgramFiles%\WhistleSoftware\
RKSOF|WhistleSoftware
UINST|Whistle Software
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WinA
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\pup
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\woualo
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Yazzle Snowball Wars
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yazzle Snowball Wars
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Yazzle Sudoku
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\YazzleSudokuGame
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , dns-look-up.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , netbios-wait.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , netsearchsoft.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.dns-look-up.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.netbios-wait.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.netsearchsoft.com
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ccaccess.dll
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Emitt
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform , ADVPLUGIN|K115|165|S-866237264|dialno
REGKE|HKEY_CURRENT_USER\Software\SiteIcons\Dialers
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pmxy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-pmxy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/comload.dll
REGKE|HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/windows/downloaded program files/unidist.ocx
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\PMT
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Ebates.
REGKE|HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\AlertSpy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AlertSpy.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiVerminser.exe\
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusProtection.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Telecom Advance\Antivirus Protection
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusSolution.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\Ad-Protect.Addin.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ad-protect.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ContraVirus.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\ExpertAntivirus.Addin.1
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\AdLoader
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Trace7
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\1das\AdLoader
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell\dnl7\tracer
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ExpertAntivirus.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\myCleanerPC
REGKE|HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\Pestbot
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Pestbot.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FindExtensions\Static\RegFreeze
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\Addins\Spy-Shield.Addin.1
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Spy-Shield.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\SpyAxe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\SpyAxe.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\spyaxe.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyDawn.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyFalcon.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHazard.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHeal.exe
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Spyware Cleaner
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareQuake.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler , {E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Spyware-Secure
AUTST|Software Soft Stop
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareLocked 3.5.exe
REGKE|HKEY_CURRENT_USER\Software\VB and VBA Program Settings\VBouncer
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\virus-bursters.exe\
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\VirusProtectPro 3.4.exe 3.4
DIREC|%ProgramFiles%\Common Files\WinSoftware\
RKSOF|WinSoftware\WinAntiSpyware 2005\
DIREC|%allusersprofile%\Application Data\WinSoftware\WinAntiVirus 2005\
DIREC|%userprofile%\Application Data\WinSoftware\WinAntiVirus 2005\
RKSOF|winsoftware\winantivirus 2005
RKSOF|winsoftware\winantivirus 2005 trial
DIREC|%commonprogramfiles%\winsoftware\
RKSOF|WinSoftware
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\WinHound spyware remover
Scanning for %s ...cIt is recommended that you reboot your PC after the removal of software.

ExeRefs
--------------------------------------------------
FILEN|surfairys.exe
AUTST|cashplusmedia.exe
FILEN|ssk.exe
FILEN|ssk3repairinstall.exe
FILEN|ssk3_b5 seedcorn 4.exe
FILEN|surfsidekick.exe
FILEN|syncroad.exe
FILEN|tagasaurus.exe
FILEN|tagasuarus97.exe
FILEN|133_funtarget_4_0_4_0.exe
FILEN|tsinstall_4_0_3_8_b17.exe
FILEN|tsinstall_4_0_4_0_b4.exe
FILEN|%systemroot%syssfitb.exe
FILEN|tgdc.exe
FILEN|ucmoreiex.exe
RKSOF|Microsoft\Windows\CurrentVersion\App Paths\TinkoPal.exe
RKSOF|TinkoPal.exe
AUTST|Zstb.exe
FILEN|zsearch.exe
FILEN|zstb.exe
FILEN|winupie.exe
FILEN|trustinpopups.exe
FILEN|%windir%\tvm_b5.exe
AUTST|djtopr1150.exe
FILEN|unibar.exe
FILEN|vsolutions.exe
FILEN|bi_prob.exe
FILEN|sysvx.exe
FILEN|%userprofile%\desktop\WeatherscopeSetup.exe
FILEN|weatherscope.exe
FILEN|weatherscopesetup.exe
FILEN|whagent.exe
FILEN|whagent_update.exe
FILEN|whcc-giant.exe
FILEN|whcc_realeuser.exe
FILEN|whinstaller.exe
FILEN|whsurvey.exe
FILEN|edowst3.exe
FILEN|zcwedowst3.exe
FILEN|websecurealert.exe
FILEN|websecurealertsetup.exe
FILEN|websecureuninstaller.exe
FILEN|vvsni_sync_webinst.exe
FILEN|vvsn.exe
FILEN|whse_pb.min.g2inst.exe
FILEN|vvsn_fanz0110inst.exe
AUTST|WhenUStart.exe
FILEN|vvsni_pbtb0100inst.exe
FILEN|saveinstcm.exe
FILEN|saveuninst.exe
FILEN|saveupdate.exe
FILEN|setupsavenow.exe
FILEN|vvsni_savenowsiteinst.exe
FILEN|setupweathercast.exe
FILEN|weatherinst.exe
FILEN|weirdontheweb_topc.exe
FILEN|mediaaccess.exe
FILEN|mediaacck.exe
FILEN|winad.exe
FILEN|winka.exe
FILEN|msupdater.exe
FILEN|mynexus.exe
FILEN|webnexus.exe
FILEN|wnad-update.exe
FILEN|wnad.exe
FILEN|bobsaver.exe
FILEN|popunder.exe
FILEN|xtcfgloader.exe
FILEN|xtcfgrunner.exe
FILEN|xupiterstartup.exe
FILEN|xupiterstartup2003.exe
FILEN|xupitertoolbarinstaller.exe
FILEN|xupitertoolbarloader.exe
FILEN|xupiterwauninstaller.exe
FILEN|best.exe
FILEN|yazzle1119oinuninstaller.exe
FILEN|yazzle1264oinadmin.exe
FILEN|yazzle1264oinuninstaller.exe
FILEN|yazzlebundle-1264.exe
AUTST|FT_SilentSudokuInstaller.exe
FILEN|ageu_silentsudokuinstaller.exe
FILEN|ageu_sudokuinstaller.exe
FILEN|ft_silentsudokuinstaller.exe
FILEN|gs_silentsudokuinstaller.exe
FILEN|yazzle1119oinadmin.exe
FILEN|yazzlebundle-1119.exe
FILEN|yazzlebundle-1304.exe
FILEN|yazzlebundle-1438.exe
FILEN|yazzlebundle-1452.exe
FILEN|waterfalls1awfree.exe
FILEN|yourscreen_4_pch.exe
FILEN|yoursitebar.exe
FILEN|adstartup.exe
FILEN|%programfiles%\zango\zango.exe
FILEN|zango.exe
FILEN|zangoinstaller.exe
FILEN|zangomuncher.exe
FILEN|zangotbuninstaller.exe
FILEN|jadeshadowinstall.exe
FILEN|jadeshadowsetup.exe
FILEN|zapspot.exe
FILEN|dwdsregt.exe
FILEN|zicorn001.exe
FILEN|icont.exe
FILEN|%windir%\system32\spiven.exe
FILEN|zipclix.exe
FILEN|axdlplug-1.5.0.0-0281-setup.exe
FILEN|axdlplug-1.5.0.0-147-setup.exe
FILEN|npdlplug-1.5.0.0-147-setup.exe
FILEN|%systemdrive%\msole32.exe
FILEN|opensite.exe
FILEN|absolu-trans.exe
REGKE|HKEY_CLASSES_ROOT\AppID\exengd.EXE
FILEN|int179663.exe
FILEN|gdnus208.exe
AUTST|addot.exe
FILEN|adult_chat.exe
FILEN|tibs3.exe
FILEN|dbn1742.exe
FILEN|%Windir%\system32\dsldbaccess.exe
FILEN|%Windir%\system32\Geaccess.exe
FILEN|2da45.exe
FILEN|beauty[schoenerwerden,1].exe
FILEN|cocktails[ccp-10097,de].exe
FILEN|gifsworld[gwd-10927,de].exe
FILEN|hausaufgaben[hun-10002,de].exe
FILEN|hausaufgaben[hun-10222,de].exe
FILEN|horoskop_erstellen[aie-10070,de].exe
FILEN|lehrstellen[lhs-10004,de].exe
FILEN|liebesbriefe[lbi-10023,de,start].exe
FILEN|pflanzen[pla-10006,de].exe
FILEN|routenplanerag.exe
FILEN|sagen.exe
FILEN|satanismus.exe
FILEN|satfrequenzen.exe
FILEN|scheisse[schei1,1].exe
FILEN|schulstadt-1.exe
FILEN|schulstadt-2.exe
FILEN|schulstadt-3.exe
FILEN|schulstadt-4.exe
FILEN|schulstadt-5.exe
FILEN|schulstadt-6.exe
FILEN|schulstadt-7.exe
FILEN|schulstadt.exe
FILEN|schwanger.exe
FILEN|setup(1-1md-0-0-,us)-1.exe
FILEN|sexworld[sexworld,1].exe
FILEN|sharing-ag-1.exe
FILEN|sharing-ag.exe
FILEN|slowenien.de.exe
FILEN|smiley[smileycastle,1].exe
FILEN|smiley[syc-10008,1].exe
FILEN|smilie-fabrik.exe
FILEN|sms-stadt-1.exe
FILEN|sms-stadt-2.exe
FILEN|sms-stadt-3.exe
FILEN|sms-stadt.exe
FILEN|sms-tool.exe
FILEN|songtexte[sgx-10001,1].exe
FILEN|songtextzone-1.exe
FILEN|songtextzone-2.exe
FILEN|songtextzone-4.exe
FILEN|spass4u[s4e-10020,1].exe
FILEN|spasspilot-1.exe
FILEN|spicktricks[ree-10323,de].exe
FILEN|spieledownload[ssg-10001,1,a63e].exe
FILEN|spieleindex[spieleindex,1].exe
FILEN|spiele_runterladen[geg-10066,1].exe
FILEN|sprueche.exe
FILEN|stammbaum.de.exe
FILEN|starfuck.exe
FILEN|stars-nackt.exe
FILEN|sternzeichen[szn-10011,de].exe
FILEN|straflos[anti-report,1].exe
FILEN|suchmaschinen-1.exe
FILEN|supergames[supergames,1].exe
FILEN|taroskop.exe
FILEN|tattoo-1.exe
FILEN|tattoo-2.exe
FILEN|tattoopalace-11.exe
FILEN|tattoos[tod-10109,de].exe
FILEN|tattoos[tod-10133,1].exe
FILEN|tattoovorlagen-de[toe-10362,1]-2.exe
FILEN|tattoo[tattoomania,1].exe
FILEN|tattoo[toe-10082,1].exe
FILEN|template-tempel.exe
FILEN|tests[iqwelt,1].exe
FILEN|test[teh-10116,de,start4].exe
FILEN|tierbabys[tierbabys,1].exe
FILEN|toprezept.exe
FILEN|trilian[trilian-de,1].exe
FILEN|tuerkei.exe
FILEN|turkgays[tks-10001,1].exe
FILEN|umsatzsteigern[uee-10001,1].exe
FILEN|valueradio-1.exe
FILEN|vornamen.exe
FILEN|vornamen[vnf-10049,1].exe
FILEN|vornamen[vnf-10103,1].exe
FILEN|wetter-basis-1.exe
FILEN|wetter-basis.exe
FILEN|witzealarm.exe
FILEN|witze[counterde,1].exe
FILEN|wohnung.exe
FILEN|maxd641.exe
FILEN|syslcznp.exe
AUTST|ciakaisen.exe
AUTST|lateshow.exe
AUTST|wke.exe
FILEN|%USERPROFILE%\Start Menu\messaggio3.exe
AUTST|sws.exe
FILEN|gd-ff_be.exe
FILEN|gd-ff_us.exe
FILEN|gdnca167.exe
FILEN|hacker spider.exe
FILEN|123-sexkino.exe
FILEN|aktgirls.exe
FILEN|aktshow.exe
FILEN|amateur-hardcore-sex.exe
FILEN|analorgasmus.exe
FILEN|analxxx.exe
FILEN|babesex.exe
FILEN|begleitung-online.exe
FILEN|berlin-erotik.exe
FILEN|betnaker.exe
FILEN|bigbusen.exe
FILEN|bumsmich.exe
FILEN|bundesligagirls.exe
FILEN|busencam.exe
FILEN|busenline.exe
FILEN|busenshow.exe
FILEN|busentreff.exe
FILEN|busenweb.exe
FILEN|camcontrol.exe
FILEN|casarossa.exe
FILEN|city-girls.exe
FILEN|clickfick.exe
FILEN|computersex.exe
FILEN|cyber-angels.exe
FILEN|cybererotiva.exe
FILEN|debabes.exe
FILEN|degirls.exe
FILEN|deutsch.exe
FILEN|devotelust.exe
FILEN|disnex.exe
FILEN|donnavargas.exe
FILEN|dream-sex.exe
FILEN|e-kontakte.exe
FILEN|ecsfun.exe
FILEN|ero-world.exe
FILEN|eroclick.exe
FILEN|eroklick.exe
FILEN|erophone.exe
FILEN|eroplanet.exe
FILEN|erotic-news.exe
FILEN|eroticenter.exe
FILEN|eroticliveshow.exe
FILEN|erotik-news.exe
FILEN|euromodels2.exe
FILEN|fickclick.exe
FILEN|fickenonline.exe
FILEN|fickklick.exe
FILEN|fickline.exe
FILEN|fickschule.exe
FILEN|ficksie.exe
FILEN|fussballgirls.exe
FILEN|germany.exe
FILEN|gina-wild-sex.exe
FILEN|girls.exe
FILEN|girlsbesuch.exe
FILEN|girlshotel.exe
FILEN|girlstalk.exe
FILEN|glas-haus.exe
FILEN|hardcore-live-sex.exe
FILEN|hooters.exe
FILEN|hotbunny.exe
FILEN|hotelbesuch.exe
FILEN|hotelgirls.exe
FILEN|hotpower.exe
FILEN|hotvot.exe
FILEN|hotwied.exe
FILEN|klickfick.exe
FILEN|kontaktechat.exe
FILEN|lesbenhaus.exe
FILEN|life-girl.exe
FILEN|lifegirl.exe
FILEN|live-studio.exe
FILEN|livechatcam.exe
FILEN|livephone.exe
FILEN|livesex.exe
FILEN|livesexkanal.exe
FILEN|liveshow.exe
FILEN|lovephone.exe
FILEN|lucky-punch.exe
FILEN|macronedia.exe
FILEN|maxxcafe.exe
FILEN|meetboys.exe
FILEN|meinecam.exe
FILEN|moesenhaus.exe
FILEN|mytits.exe
FILEN|nacktshow.exe
FILEN|nudeliveshow.exe
FILEN|online-begleitung.exe
FILEN|online-escort.exe
FILEN|orgasmusbilder.exe
FILEN|orgasmusline.exe
FILEN|orgasmuslive.exe
FILEN|orgasmusparty.exe
FILEN|orgasmusvideo.exe
FILEN|osnastrip.exe
FILEN|pagesex.exe
FILEN|pam.exe
FILEN|peep-show-girls.exe
FILEN|persiankitti.exe
FILEN|persianklitty.exe
FILEN|phonegirl.exe
FILEN|phythom.exe
FILEN|playboobs.exe
FILEN|playgal.exe
FILEN|playmoesen.exe
FILEN|playmuschi.exe
FILEN|porncam.exe
FILEN|porno-porno-sex-sex.exe
FILEN|pornodelux.exe
FILEN|pornomoesen.exe
FILEN|privatbesuch.exe
FILEN|pussygeil.exe
FILEN|pussyhaus.exe
FILEN|redlightgirls.exe
FILEN|rotlichtchat.exe
FILEN|rotlichtgirls.exe
FILEN|rotlichtline.exe
FILEN|rotlichtshow.exe
FILEN|schulsex.exe
FILEN|sex-erotik-show.exe
FILEN|sex-live-chat.exe
FILEN|sex-porno-show.exe
FILEN|sex-rooms.exe
FILEN|sex-sex-porno-porno.exe
FILEN|sex-sex-sex-pussy.exe
FILEN|sex-tabulos.exe
FILEN|sexcall.exe
FILEN|sexdominanz.exe
FILEN|sexevents.exe
FILEN|sexfetish.exe
FILEN|sexillusion.exe
FILEN|sexkarussell.exe
FILEN|sexkeller.exe
FILEN|sexme.exe
FILEN|sexmich.exe
FILEN|sexpicturegallery.exe
FILEN|sexroulette.exe
FILEN|sexschule.exe
FILEN|sextacy.exe
FILEN|sexycamera.exe
FILEN|smutlamd.exe
FILEN|soos.exe
FILEN|strapsshow.exe
FILEN|strichgirls.exe
FILEN|strip-eonline.exe
FILEN|strip-girls.exe
FILEN|stripcan.exe
FILEN|striplime.exe
FILEN|stripline.exe
FILEN|strippenonline.exe
FILEN|stripschule.exe
FILEN|studiosex.exe
FILEN|suendenspiele.exe
FILEN|teenmail.exe
FILEN|telestrip.exe
FILEN|the-sweets.exe
FILEN|tittengeil.exe
FILEN|tittenline.exe
FILEN|tittenseite.exe
FILEN|tittenspiele.exe
FILEN|tittenweb.exe
FILEN|tittenwelt.exe
FILEN|travelsex24.exe
FILEN|venusgirls.exe
FILEN|venusphone.exe
FILEN|victoriasecreet.exe
FILEN|videochatcam.exe
FILEN|viona.exe
FILEN|vollbusicam.exe
FILEN|wichsen.exe
FILEN|wild-sex.exe
FILEN|xxxphone.exe
FILEN|hotactiondating-uninstall.exe
FILEN|hotactiondating.exe
FILEN|nsi145.exe
FILEN|gratis-sex-crack.exe
FILEN|traumdate.exe
FILEN|iedisco.exe
FILEN|view_sex_now.exe
FILEN|net900.exe
FILEN|od-dflt0001.exe
FILEN|od-stnd191.exe
FILEN|%systemroot%\Orgasm.exe
FILEN|30500105.exe
FILEN|parisvoyeur.exe
FILEN|browser_plugin.exe
FILEN|hotsurprise_be.exe
FILEN|ukvideo2.exe
AUTST|bodr.exe
FILEN|britney spears nackt.exe
FILEN|hzs-10030.exe
FILEN|stripsetup.exe
FILEN|systemvxd.exe
FILEN|clbmn2.exe
FILEN|tibsloader.exe
FILEN|adult.exe
FILEN|cammaus.exe
FILEN|deutsche-peepshow.exe
FILEN|erotik-hotel.exe
FILEN|funland.exe
FILEN|lustmaus.exe
FILEN|megabusen.exe
FILEN|nutte.exe
FILEN|sabine.exe
FILEN|sabine2.exe
FILEN|sexstop.exe
FILEN|spanner.exe
FILEN|stchat.exe
FILEN|telefun.exe
FILEN|tscash.exe
FILEN|ueber40de.exe
FILEN|xxxlivesex.exe
FILEN|23aw0001.exe
FILEN|arr.exe
FILEN|belgium_sex-uninstall.exe
FILEN|crush.exe
FILEN|datemakerintl.exe
FILEN|direktsex.exe
FILEN|freesexx.exe
FILEN|go in.exe
FILEN|handy-paradies.exe
FILEN|hardcoreteens.exe
FILEN|hotsex.exe
FILEN|hotsexvideos.exe
FILEN|hot_canada.exe
FILEN|lolitasex.exe
FILEN|od-stnd24.exe
FILEN|piratos.exe
FILEN|pissing.avi.exe
FILEN|sexy-uninstall.exe
FILEN|sexy_belgium-uninstall.exe
AUTST|\windows\syswin.exe
FILEN|agrit.exe
FILEN|alberghi.exe
FILEN|qualsiasi.exe
FILEN|xxlav003.exe
FILEN|xdiver.exe
FILEN|xgenius.exe
FILEN|almaster.exe-34cdc7f0.pf
FILEN|backdoor.hacktack.110.exe
FILEN|backdoor.hacktack.112.exe
FILEN|backdoor.hacktack.120.b.exe
FILEN|backdoor.hacktack.exe
AUTST|djebmm350.exe
FILEN|disp350.exe
FILEN|ebatesmoemoneymaker.exe
FILEN|ebatesmoemoneymaker1.exe
FILEN|websavingsfromebates.exe
FILEN|websavingsfromebates0.exe
FILEN|disp1150.exe
FILEN|sahagent-seedcorn1002.exe
FILEN|w11150.exe
FILEN|webrebates.exe
FILEN|webrebates0.exe
FILEN|webrebates1.exe
FILEN|webrebates2.exe
FILEN|webrebatesrun.exe
FILEN|webrebates_auto_installsilent.exe
FILEN|alexainstaller.exe
FILEN|mksc.exe
FILEN|ossproxy.exe
FILEN|rlvknlg.exe
FILEN|nhupdater.exe
FILEN|http-tunnelclient.exe
FILEN|httptunnelinstallerv403065.exe
AUTST|AdArmor.exe Monitor
FILEN|adarmor.exe
FILEN|adarmorinstaller.exe
FILEN|adarmor_monitor.exe
FILEN|adarmor_updater.exe
FILEN|ads adware remover.exe
FILEN|adsremover.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AlertSpy.exe
FILEN|alertspy.exe
FILEN|alfacleaner.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntiVerminser.exe\
FILEN|antiverminser.exe
FILEN|av_setup.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusProtection.exe
FILEN|antivirusprotection.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\AntivirusSolution.exe
FILEN|antivirussolution.exe
FILEN|antivirus_solution_setup_1.0.0.exe
FILEN|bravesentry.exe
FILEN|bravesentrysetup.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ad-protect.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ContraVirus.exe
FILEN|%temp%\ContraVirus 2.0 Installer.exe
FILEN|contravirus.exe
FILEN|contraviruspro.exe
FILEN|cv_1_setup.exe
FILEN|xpuupdate.exe
FILEN|%allusersprofile%\Start Menu\Programs\Startup\Start CurePCSolution.exe.lnk
FILEN|curepcsolution.exe
FILEN|udc2006.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ExpertAntivirus.exe
CLASS|ad-protect.EXE
FILEN|expertantivirus.exe
AUTST|FixerAntispy.exe Monitor
FILEN|fixerantispy.exe
FILEN|fixerantispyinstaller.exe
FILEN|fixerantispy_monitor.exe
FILEN|fixerantispy_updater.exe
FILEN|killandclean.exe
FILEN|killandcleansetup.exe
FILEN|killandcleanupdate.exe
FILEN|malwarestopper.exe
FILEN|malwarestoppersetup.exe
FILEN|isec30.exe
FILEN|perfectcleaner.exe
FILEN|perfectcleaner_setup.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Pestbot.exe
FILEN|pestbot.exe
FILEN|pestcapture.exe
FILEN|pestcapturesetup.exe
FILEN|regfreeze.exe
REGKE|HKEY_CLASSES_ROOT\AppID\ad-protect.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Spy-Shield.exe
FILEN|spyaway.exe
FILEN|spyaway_setup.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\SpyAxe.EXE
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\spyaxe.exe
FILEN|spycrush.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyDawn.exe
FILEN|spydawn.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyFalcon.exe
FILEN|atmclk.exe
FILEN|spyfalcon.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHazard.exe
FILEN|spyhazard.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpyHeal.exe
FILEN|spymarshal.exe
FILEN|spysoldier.exe
FILEN|spysoldier_setup.exe
FILEN|spyvampire.exe
FILEN|spyvampire_1.0.1.311_install.exe
FILEN|%userprofile%\Desktop\SCFree.exe
FILEN|%userprofile%\SCFree.exe
FILEN|spyclean.exe
FILEN|spywinclean.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareQuake.exe
FILEN|%WINDir%\system32\atmclk.exe
FILEN|%WINDir%\system32\dcomcfg.exe
FILEN|spy-quake2.exe
FILEN|%temp%\NSIS_SpywareSecure_trial_setup.exe
FILEN|spyware-secure_trial.exe
FILEN|spywaresecure_trial_setup.exe
FILEN|slimshieldinstall.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SpywareLocked 3.5.exe
FILEN|spywarelocked 3.5.exe
FILEN|spywarelocked.exe
FILEN|spysheriff.exe
FILEN|spywarestrike.exe
FILEN|ss_setup.exe
FILEN|%windir%\SGPro.exe
FILEN|sgpro.exe
FILEN|sg_free.exe
FILEN|%windir%\downloaded program files\usdr6_0001_d08m0404netinstaller.exe
FILEN|sd2006.exe
FILEN|systemdoctor2006freeinstall.exe
FILEN|systemdoctorfreesetup.exe
AUTST|a856cdb1.exe
FILEN|bundleouter2601031121.exe
FILEN|vb2uninstaller4_19.exe
FILEN|vbouncerinner.exe
FILEN|vbouncerinner1007.exe
FILEN|vbouncerinner1106.exe
FILEN|vbouncerinner1107.exe
FILEN|vbouncerinner1108.exe
FILEN|vbouncerinner1109.exe
FILEN|vbouncerouter1123030429.exe
FILEN|vbouncerouter1203.exe
FILEN|virtualbouncer.exe
FILEN|virtual_bouncer.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\virus-bursters.exe\
FILEN|vb_distrib.exe
FILEN|virus-bursters.exe
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\VirusProtectPro 3.4.exe 3.4
FILEN|VirusProtectPro 3.4.exe
AUTST|hclean32.exe
FILEN|wareoutupdate.exe
AUTST|fat.exe
FILEN|%USERPROFILE%\desktop\WinFixerScannerInstall.exe
FILEN|wfx5.exe
FILEN|winfixer2005trialsetup.exe
FILEN|%userprofile%\Desktop\WinHoundinstaller.exe
FILEN|%windir%\WinHoundInstaller.exe
FILEN|winhound.exe
FILEN|worldantispy.exe
FILEN|evcztdq_pinch.exe
FILEN|qmtsfzh_pinch.exe

Raw Strings:
--------------------------------------------------
FILEN|surfairypp.dll
FILEN|surfairys.exe
NEWPR|1128|SurfSideKick
PRCAT|5
CLSID|{000ab005-ff12-42c2-8df5-39e12e5f9c91}
CLSID|{02ee5b04-f144-47bb-83fb-a60bd91b74a9}
CLSID|{4a2283c2-4d10-4954-1bbc-b730a621813c}
CLSID|{ca0e28fa-1afd-4c21-a8dc-70eb5be2f076}
CLSID|{fa89e1b0-e902-6968-bea5-156ab2fc177b}
DIREC|%CommonProgramFiles%\vcclient\
DIREC|%ProgramFiles%\SurfSideKick 2\
DIREC|%ProgramFiles%\SurfSideKick 3\
DIREC|%programfiles%\SurfSideKick\
AUTST|cashplusmedia.exe
AUTST|cyshgd
AUTST|dB2qRTc5T
AUTST|DNS
AUTST|Ebwh
AUTST|ezisde
AUTST|GsAds
AUTST|kpfbph
AUTST|KwtFRTc2W
AUTST|lfecqh
AUTST|lqxcx
AUTST|MedGS
AUTST|mqwf
AUTST|mtzfcv
AUTST|opr
AUTST|pstdae
AUTST|qppxjf
AUTST|Qwnoyep
AUTST|SurfSideKick
AUTST|SurfSideKick 2
AUTST|SurfSideKick 3
AUTST|Windows Incontext
AUTST|xeqdnc
RKSOF|SurfSideKick
RKSOF|SurfSideKick2
RKSOF|SurfSideKick3
UINST|Surf SideKick
UINST|Surf Sidekick_is1
FILEN|repairs303169536.dll
FILEN|repairs303169590.dll
FILEN|ssk.exe
FILEN|ssk3repairinstall.exe
FILEN|ssk3_b5 seedcorn 4.exe
FILEN|sskbho.dll
FILEN|sskcore.dll
FILEN|sskcwrd.dll
FILEN|sskffcore.dll
FILEN|sskknwrd.dll
FILEN|sskuknwrd.dll
FILEN|surfsidekick.exe
NEWPR|2487|SweetBar
PRCAT|5
CLSID|{21ba3ee1-ccc9-4381-9997-928127b0c2d6}
CLSID|{68a7f9fa-a202-4d45-aaba-a10dcac0d899}
DIREC|%AllUsersProfile%\Start Menu\Programs\SweetBox\
DIREC|%ProgramFiles%\SweetBox\
AUTST|SweetBox
CLASS|SweetBox.SweetActive
RKSOF|SweetBar
SERVK|IPRIP
NEWPR|1697|SwimSuitNetwork
PRCAT|5
AUTST|swimsuitnetwork
NEWPR|979|SyncroAd
PRCAT|5
DIREC|%programfiles%\Windows SyncroAd
AUTST|Windows SyncroAd
UINST|Windows SyncroAd
FILEN|%SystemRoot%\System32\ide21201.vxd
FILEN|syncroad.exe
NEWPR|730|Syscpy
PRCAT|5
NEWPR|2465|System Process
PRCAT|5
CLSID|{2588bbaa-f6c6-0053-c746-05ce98d3d296}
CLSID|{465f66ce-d075-cca7-7426-098c0e74be6d}
CLSID|{49ae83eb-5b19-7104-6a65-0b52de3de139}
CLSID|{5064a992-9575-e73c-c514-0a4cb0eb764c}
CLSID|{688b592e-4ab8-49a6-f9b2-02b3db5f7b0a}
CLSIA|{9bb5b49c-0d59-418d-a6a5-f6373b8fef64}
CLSID|{c2eeb4fa-b6d6-41b9-9cfa-aba87f862bcb}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , *.system-processes
DIREC|%ProgramFiles%\BHO Plugin\
RKSOF|BHO
RKSOF|BHO\icons
RKSOF|System Process
UINST|Startup
SERVK|TCP and UDP Support
NEWPR|1168|System Soap Pro
PRCAT|5
AUTST|%ProgramFiles%\System Soap Pro
AUTST|System Soap Pro
RKSOF|system soap
UINST|System Soap Pro 3.2-AC1
NEWPR|1813|System61
PRCAT|5
CLSID|{c7967580-5f17-11d4-aac2-0000b4936e0c}
NEWPR|2785|TagAsaurus
PRCAT|5
DIREC|%programfiles%\Tagasaurus\
AUTST|TagASaurus
AUTST|win32094-86623726
FILEN|tagasaurus.exe
FILEN|tagasuarus97.exe
NEWPR|1914|TargetSavers
PRCAT|5
DIREC|%CommonProgramFiles%\ffor\
DIREC|%CommonProgramFiles%\tsa\
DIREC|%windir%\ffor\
AUTST|ffor
RKSOF|ffor
RKSOF|fqmq
RKSOF|mrqf
RKSOF|TSA
UINST|TSA
UINST|TSAUNINST
UINST|TSL Installer
FILEN|133_funtarget_4_0_4_0.exe
FILEN|tsinstall_4_0_3_8_b17.exe
FILEN|tsinstall_4_0_4_0_b4.exe
NEWPR|1701|Tatss
PRCAT|5
NEWPR|627|Tellafriend
PRCAT|5
CLSID|{5297e905-1dfb-4a9c-9871-a4f95fd58945}
CLSIA|{72a58725-2635-4725-8c53-676dfd1feb8d}
CLSID|{95b92d92-8b7d-4a19-a3f1-43113b4dbcaf}
RKSOF|zeropopup
FILEN|zp.cab
NEWPR|1703|TestTimer
PRCAT|5
FILEN|%systemroot%syssfitb.exe
NEWPR|424|TGDC
PRCAT|5
CLSIA|{05bbb56a-2a69-4a5c-bfda-43295dd67434}
AUTST|TGDC IE Plugin
FILEN|tgdc.exe
NEWPR|776|The Search Accelerator
PRCAT|5
CLSID|{3131a8d2-d92c-48ba-96ac-8a77d6a1d573}
CLSID|{33740aeb-2856-4004-b84b-37e2c0d4f13d}
CLSID|{44be0690-5429-47f0-85bb-3ffd8020233e}
CLSIA|{53cbee82-d747-11d3-9ed0-005004189684}
CLSIA|{607df741-7d0a-11d4-9edc-005004189684}
CLSID|{aae89d95-75cc-4708-87e5-60cf917b7b5b}
CLSIA|{ed8db0fd-d8f4-4b2c-bb5b-9ef040fe104d}
REGKE|HKEY_CURRENT_USER\Software\Maxthon\Plugin\toolbar\{44BE0690-5429-47f0-85BB-3FFD8020233E}
DIREC|%ProgramFiles%\TheSearchAccelerator\
DIREC|%programfiles%\UCmore\
DIREC|%userprofile%\Start Menu\Programs\UCmore - The Search Accelerator\
RKSOF|Effective-i
RKSOF|ucmore
RKSOF|UCmore.UcmoreTsaApp
UINST|UCmore - The Search Accelerator
FILEN|ucmie.dll
FILEN|ucmoreiex.exe
FILEN|ucmtsaie.dll
NEWPR|3046|Themexp
PRCAT|5
UINST|Themexp.org File
NEWPR|3161|Think-Adz
PRCAT|5
UINST|Enhanced Ads by Think-Adz
UINST|Think-Adz Search Assistant
NEWPR|2232|TinkoPal
PRCAT|5
DIREC|%ProgramFiles%\TinkoPal
DIREC|%USERPROFILE%\Start Menu\Programs\TinkoPal
RKSOF|Microsoft\Windows\CurrentVersion\App Paths\TinkoPal.exe
RKSOF|TinkoPal.exe
UINST|TinkoPal
FILEN|%USERPROFILE%\Desktop\TinkoPal.lnk
NEWPR|496|TinyBar
PRCAT|5
CLSIA|{69555be2-9a78-11d2-ba91-00600827878d}
CLSIA|{82599e0a-8c81-11d7-9f97-0050fc5441cb}
CLSIA|{8fb0f3e2-5193-11d7-9f88-0050fc5441cb}
NEWPR|2235|ToolBar.SBSoft.h
PRCAT|5
CLSIA|{bf8e8df4-fae4-4df4-acc0-d25ec1010714}
CLASS|TORUTORUX.ToruToruXCtrl
NEWPR|681|ToolbarCC
PRCAT|5
CLSIA|{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffa2}
CLSIA|{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffa6}
CLSIA|{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffa7}
CLSIA|{1f48aa48-c53a-4e21-85e7-ac7cc6b5ffa8}
NEWPR|1258|ToonComics
PRCAT|5
AUTST|fqdin
AUTST|iedll
NEWPR|2516|Top20results
PRCAT|5
NEWPR|2645|Topfive searchAssistant
PRCAT|5
DIREC|%ProgramFiles%\TopSearch\
AUTST|TopSearch
RKSOF|TopMoxie\TopSearch
UINST|TopSearch
NEWPR|613|TOPicks
PRCAT|5
CLSID|{02cdb0ed-874a-4dcb-8d9f-c2e3b169f265}
CLSIA|{0352960f-47be-11d5-ab93-00d0b760b4eb}
CLSID|{16097036-894c-4c00-a61f-93ca0d49a70e}
CLSIA|{1717a4a5-d63a-4f70-b373-ae4aa46d1236}
CLSID|{1b540d44-3f61-4394-ae30-25fdc3649405}
CLSID|{1d3bce37-7834-4579-8169-e67681420a98}
CLSID|{258a3625-183b-4477-aee2-ea54df6d878d}
CLSID|{29e825aa-13bc-457c-806a-d72e4a25b3c5}
CLSID|{2ed5af98-9258-45ba-b79b-06625c92f662}
CLSID|{5c40012e-44ca-11d7-8411-0002a5f9d08e}
CLSID|{700dc0dd-f409-42e0-9de5-21ee1a2ba9fd}
CLSID|{80e81a0e-9741-4fbc-8ee3-3b78c04ada1d}
CLSID|{91d91d21-8008-429d-821c-7266aac84a9f}
CLSID|{9a7cfeda-5911-4ef1-b49a-35c34230ffc1}
CLSID|{9bbcf06c-dcd7-495d-80df-cdd5399d0ff8}
CLSID|{9d4548ce-92fd-4c6c-ae7f-3dbe3bc763d8}
CLSID|{9f8ac164-6826-4b52-8f65-9c31305e81cc}
CLSID|{ad5bc1f0-72d8-44b3-8e3d-8e8fecce43fb}
CLSID|{be7613d4-7d09-4cf8-b747-6dff0564891e}
CLSID|{ce9b37ec-d243-47a2-83db-3a8350175193}
CLSID|{d273d427-57c6-4b12-860f-bbb8195f6e2a}
CLSID|{d7cb5baf-18d9-46d4-8f72-909d409506fa}
CLSID|{e79dadc6-18d0-4a2a-831f-d196d41f8438}
CLSID|{fd42f6d3-7ab1-470c-979b-7996edc99099}
AUTST|topicks starter
CLASS|HtCheck2.CheckPage
CLASS|HtChe
ck2.CHelpObj
CLASS|IdiumUpdater.IdiumSysUpdater
CLASS|ToPicksReg.ToPickReg1
NEWPR|1806|TopSurfer
PRCAT|5
CLSID|{af657644-964c-4348-a8ad-72524b3a3ff1}
NEWPR|763|TotalVelocity zSearch
PRCAT|5
CLSID|{5886a6dc-aaf4-45e9-979a-8e5e6dee30e7}
CLSIA|{828a9ed2-c5bb-4caa-bcb7-a4cc024aafd6}
DIREC|%ProgramFiles%\zSearch\
AUTST|zSearch
AUTST|Zstb.exe
UINST|zSearch_is1
FILEN|zsearch.dll
FILEN|zsearch.exe
FILEN|zstb.exe
NEWPR|1706|Townews
PRCAT|5
CLSID|{634efde4-087d-4ce9-952f-63c9eeb2e0bf}
NEWPR|565|TradeExit
PRCAT|5
CLSIA|{f0230524-9d39-4e84-8452-41c592961ea7}
FILEN|winupie.exe
NEWPR|2627|Transponder.kz515
PRCAT|5
CLSID|{c0322f4c-ab89-4c3b-94ae-56de8a4bd07d}
CLSID|{ed1282a6-4a6e-4893-85fc-6ccfd39d8377}
CLASS|kz515Dll.kz515DllObj
RKSOF|kz515
NEWPR|2372|Trojan.Zlob.E
PRCAT|5
CLSID|{1ca480cd-c0e5-4548-874e-b85b17905b3a}
CLSID|{724510c3-f3c8-4fb7-879a-d99f29008a2f}
CLSID|{7caf96a2-c556-460a-988e-76fc7895d284}
FILEN|%windir%\ncompat.tlb
FILEN|%windir%\system32\msvol.tlb
NEWPR|2814|TrustIn Bar
PRCAT|5
CLSID|{07a78aea-4a54-4967-9a60-4b68592d30c7}
CLSID|{23cb9697-2835-45c5-8949-8a4e73aa70d4}
CLSIA|{590ffb84-6a29-4797-9c0e-b15df2c4cdcb}
CLSID|{9b053e00-78d3-47ae-b763-60ff36ff2886}
CLSID|{fe6c16c4-16ad-47b6-b250-26ad1829e49a}
DIREC|%ProgramFiles%\TrustIn Bar
DIREC|%ProgramFiles%\TrustIn Contextual
DIREC|%ProgramFiles%\TrustIn Search
CLASS|InetLoader.WeeklyExecuter
CLASS|Se_spoof.SpoofBHO
CLASS|ticont.MyBHO
CLASS|tisa.MyBHO
CLASS|TrustIn.activator
CLASS|TrustIn.StockBar
CLASS|TrustInContext.ContextualAds
RKSOF|TrustIn
RKSOF|TrustIn Bar
UINST|Contextual Ads
UINST|TICONT
UINST|TISA
UINST|TrustIn Bar
NEWPR|2942|Trustin popups
PRCAT|5
DIREC|%programfiles%\TrustIn Popups\
AUTST|TrustIn Popups
RKSOF|TrustIn Popups
UINST|TrustIn Popups
FILEN|trustinpopups.exe
NEWPR|1352|Trustyfiles
PRCAT|5
DIREC|%ALLUSERSPROFILE%\TrustyFiles
DIREC|%programfiles%\TrustyFiles
RKSOF|TrustyFiles
UINST|TrustyFiles
FILEN|%USERPROFILE%\Desktop\TrustyFiles Downloads and Sharing.lnk
FILEN|%USERPROFILE%\Desktop\TrustyFiles.lnk
NEWPR|2635|TrustyHound
PRCAT|5
CLSID|{aa2ad390-5ec0-4742-a5f6-a59b50fbdaa0}
DIREC|%AllUsersProfile%\Start Menu\Programs\TrustyHound-TS\
DIREC|%ProgramFiles%\TrustyHound-TB\
DIREC|%ProgramFiles%\TrustyHound-TS\
AUTST|TrustyHound-TS
CLASS|ToolBand.XBTP01786
CLASS|XBTB01786.IEToolbar
CLASS|XBTB01786.XBTB01786
RKSOF|XBTB01786
UINST|TrustyHound-TS ( Companion Tools )_is1
UINST|XBTB01786.XBTB01786Toolbar
FILEN|%USERPROFILE%\Desktop\CardFountain Greetings.lnk
FILEN|%USERPROFILE%\Desktop\Free Stuff Directory.lnk
FILEN|%USERPROFILE%\Desktop\FunFlirts Online Dating.lnk
FILEN|%USERPROFILE%\Desktop\TrustyHound Image Search.lnk
FILEN|%USERPROFILE%\Desktop\TrustyHound Web Search.lnk
NEWPR|1086|TryToFind
PRCAT|5
CLSIA|{90baeb8b-47c2-44b4-a5a6-b99d34f1d4c5}
CLSIA|{d8c6179a-58c3-4662-800a-22dae7dcb152}
DIREC|%ProgramFiles%\Try2Find\
CLASS|sptbax.Install
RKSOF|Try2Find
NEWPR|1232|TurboDownload
PRCAT|5
CLSID|{120e090d-9136-4b78-8258-f0b44b4bd2ac}
CLSID|{1a00c40b-da85-4aa3-a67f-582d9347eecd}
DIREC|%programfiles%\Maxspeed
AUTST|IEDriver
RKSOF|MaxSpeed
RKSOF|turbodownload
NEWPR|521|TV Media Display
PRCAT|5
CLSID|{20ec3d2d-33c1-4c9d-bc37-c2d500688da2}
CLSID|{707e6f76-9ffb-4920-a976-ea101271bc25}
CLSID|{965a592f-8efa-4250-8630-7960230792f1}
DIREC|%ProgramFiles%\TV Media\
AUTST|TV Media
AUTST|TVMD
AUTST|winpoet
UINST|tv media
FILEN|%windir%\tvm_b5.exe
FILEN|tvmbho.dll
FILEN|tvmcore.dll
FILEN|tvmcwrd.dll
FILEN|tvmknwrd.dll
NEWPR|650|Twain-Tech
PRCAT|5
CLSID|{000020dd-c72e-4113-af77-dd56626c6c42}
CLSID|{0000607d-d204-42c7-8e46-216055bf9918}
AUTST|alchem
AUTST|djtopr1150.exe
AUTST|odurhdvxjj
AUTST|xgn
CLASS|Twaintec.TwaintecObj
CLASS|TwaintecDll.TwaintecDllObj
FILEN|mxtarget.dll
FILEN|twaintec.dll
NEWPR|2317|TX4
PRCAT|5
NEWPR|722|UCSearch
PRCAT|5
CLSID|{0ff7dbe0-ce7d-43b2-b016-50f1c88551e5}
CLSID|{1cbf31fc-3c23-4ba6-af16-2cec501bd837}
CLSIA|{1fdec088-a699-46fe-bf76-d5fd6dae6150}
CLSID|{4c33d68d-9703-4636-b433-383d42d0847c}
CLSID|{737263fd-a882-4957-8136-c0fd923ff150}
CLSID|{bbbe1c1a-89f7-4af6-abd1-f8fbcfa47408}
CLSIA|{e62a47d8-74b1-4a93-963a-e5e43b7cc5c2}
DIREC|%ProgramFiles%\open site\
CLASS|UCSearch.ucUCSearch
NEWPR|2666|Ultrabar
PRCAT|5
CLSID|{57a157fe-f766-46f1-8eb5-4a48be2f5daf}
CLSID|{a735e796-6ed4-4987-80e5-15b74020d978}
DIREC|%ProgramFiles%\UltraBar\
UINST|UltraBar
FILEN|%WINDIR%\Downloaded Program Files\ultrabar.inf
NEWPR|2011|Unclassified
PRCAT|5
NEWPR|3332|Unibar
PRCAT|5
CLSID|{0bbf1c37-f268-4489-8b0d-4e03f37a8dbf}
CLSID|{3221a442-e009-47f6-97c8-835462acc6b2}
CLSID|{77519220-81b7-4eff-9d40-5bc7425d4e5b}
CLSID|{841b2b65-118d-4ff2-ad63-4cff44b8b68f}
CLSID|{dbaed463-f7c8-4046-90ad-bef771cad496}
CLSID|{dfcb34b6-902d-426e-ae2b-1b294ae19f4f}
CLSID|{fd5ec997-35ab-49b6-a504-d0879643845f}
DIREC|%programfiles%\unibar\
CLASS|KWBand.CExplorerBar
CLASS|KWBand.KeyWordBand
UINST|21805fef
UINST|38616223
UINST|6fe46231
FILEN|unibar.exe
NEWPR|2099|UpSpiral Toolbar
PRCAT|5
CLSID|{4e7bd74f-2b8d-469e-deff-ed65a486aa28}
DIREC|%ProgramFiles%\Upspiral Toolbar\
CLASS|upspiral.UPSPIRAL
CLASS|upspiral.UPSPIRALMenu Button
CLASS|upspiral.UPSPIRALToggle Button
RKSOF|Upspiral Toolbar
UINST|Upspiral
NEWPR|743|URLBlaze
PRCAT|5
CLSIA|{9feffbde-fe2f-4756-b4a7-90d976255f9b}
CLSIA|{ce7c3cf0-4b15-11d1-abed-709549c10000}
DIREC|%programfiles%\urlblaze
DIREC|%USERPROFILE%\Start Menu\Programs\URLBlaze\
DIREC|%windir%\System32\IEDriver\
UINST|DMVLite
UINST|URLBlaze
FILEN|%SystemRoot%\uburl.dat
FILEN|%USERPROFILE%\Desktop\URLBlaze.lnk
NEWPR|742|Verticity
PRCAT|5
NEWPR|2614|VideoC
PRCAT|5
CLSID|{58dbce03-ffc3-4452-ab1d-c19ee9825a50}
NEWPR|1698|Viewpoint Media Toolbar
PRCAT|5
CLSID|{a7327c09-b521-4edb-8509-7d2660c9ec98}
CLSID|{f8ad5aa5-d966-4667-9daf-2561d68b2012}
DIREC|%allusersprofile%\Application Data\Viewpoint\ViewBar\
DIREC|%appdata%\Viewpoint\ViewBar\
DIREC|%programfiles%\Viewpoint\Viewpoint Toolbar\
CLASS|ViewBar.ViewBar
CLASS|ViewBarBHO.BHO
RKSOF|Viewpoint\ViewpointSearchBar
UINST|Viewpoint Manager
UINST|ViewpointSearchBar
NEWPR|2138|VipSearcher
PRCAT|5
CLSID|{0393fe81-0bbd-4bce-b4f2-c643aa7d77dd}
CLSID|{10bc40b5-5019-4a47-b033-308ca16d4959}
CLSID|{1559c6fd-8bde-476e-98c7-871e59193fce}
CLSID|{405132a4-5dd1-4ba8-a181-95c8d435093a}
CLSID|{c2e07b68-2f46-4dbb-8261-285794b7f8de}
NEWPR|1707|VirtuMonde
PRCAT|5
CLSID|{13589181-4f0d-4553-b9f8-b4b72172c139}
CLSID|{18722863-6d1d-4300-bf29-406948eda7cb}
CLSID|{30279f2d-1a38-4785-97d4-5c3508bdb289}
CLSID|{3ec8e271-fab9-418a-8a8e-65aeb4029e64}
CLSID|{446cf8a5-617e-4d91-95ae-ae78ce0d06af}
CLSID|{44e5b409-35a2-4e8d-bf94-344222323a53}
CLSID|{55e301e5-ba44-4095-bb0b-14e0123ccf71}
CLSID|{60112085-e1ce-4e0e-823a-ebb1ad98804c}
CLSID|{68132581-10f2-416e-b188-4e648075325a}
CLSID|{69eab151-c904-4734-aa74-a952290c5387}
CLSID|{6a06cdad-9d2d-42a0-9c91-c0cf7cb9971b}
CLSID|{6d33b121-5c4c-4450-9d1f-7b67085cc199}
CLSID|{72ac6865-b1d3-4c32-a27b-4b3bf04de655}
CLSID|{73529697-d46a-4f7d-8a93-01378fcaeda4}
CLSID|{77849d67-5672-4b68-93e2-cceff1e3949e}
CLSID|{8109af33-6949-4833-8881-43dcc232b7b2}
CLSID|{870b70d4-f6da-47ae-9158-d146440a0a4d}
CLSID|{bf755b85-ea69-4f58-9a59-d85f384a15ff}
CLSID|{c69fa570-7fde-4c49-a7bc-cb1cf24be66b}
CLSID|{d38439ec-4a7f-42b4-90c2-d810d7778fdd}
CLSID|{d6964fd8-3af1-4a2a-abb7-3d0c62924fd6}
CLSID|{d9511bf5-3c27-40ac-96da-2f439720efec}
CLSID|{df57feb6-9bce-45e3-aa65-be327b8cce7f}
CLSID|{ed5abc42-8e4f-4c39-9972-f0cf619d672f}
CLSID|{f32f8ecd-6cf3-459d-82f2-9738392c85a8}
CLSID|{fc148228-87e1-4d00-ac06-58dcaa52a4d1}
CLSID|{fd8609ec-7d7c-4778-ab8f-0053245550ef}
CLSID|{ff31c059-428b-4f07-bd1b-8f5dad170182}
AUTST|*catw
AUTST|ddayv
AUTST|pmnkk
AUTST|pmnlj
AUTST|windowsupd
FILEN|%systemroot%\system32\cbxwx.dll
NEWPR|2580|Virutek
PRCAT|5
AUTST|smsys
NEWPR|1811|Vividence Connector
PRCAT|5
CLSID|{c3bcc488-1ae7-11d4-ab82-0010a4ec2338}
NEWPR|2865|VMCleaner
PRCAT|5
NEWPR|2236|VoiceIP
PRCAT|5
REGKE|HKEY_CURRENT_USER\Software\VoiceIP
CLASS|VoiceIPDll.VoiceIPDllObj
NEWPR|912|Voonda Toolbar
PRCAT|5
CLSIA|{4e7bd74f-2b8d-469e-d4ff-eb2cf4d5fa7d}
NEWPR|1274|VroomSearch
PRCAT|5
CLSIA|{dab941d8-bc94-4819-ab4d-5598c65fa3fe}
CLSID|{f0c08b30-ba30-4feb-924b-2e250cf0697d}
AUTST|Tsa2
AUTST|Tsl2
NEWPR|3440|VSToolbar
PRCAT|5
CLSID|{74dd705d-6834-439c-a735-a6dbe2677452}
CLSID|{7addcf69-1cd5-4a57-8055-bb955805d918}
DIREC|%programfiles%\VSToolbar\
DIREC|%userprofile%\Local Settings\Application Data\VSolutions\
RKSOF|VSolutions
UINST|VSolutions Toolbar
FILEN|vsadd-in.dll
FILEN|vsolutions.exe
NEWPR|25|VX2
PRCAT|5
CLSID|{00000000-59d4-4008-9058-080011001200}
CLSIA|{00000000-5eb9-11d5-9d45-009027c14662}
CLSID|{00000026-8735-428d-b81f-dd098223b25f}
CLSID|{0000005d-c175-4405-bac5-1f3b2baf67c6}
CLSID|{00000062-2e5f-4af7-986e-5b64e0951a96}
CLSID|{00000097-7c67-4ba6-8b42-05128941688a}
CLSID|{0000026a-8230-4dd4-be4f-6889d1e74167}
CLSIA|{00000580-c637-11d5-831c-00105ad6acf0}
CLSID|{2cfb0ffd-a768-41d3-9b2d-059b80d03610}
CLSIA|{4cbbc676-507f-11d0-b98b-000000000000}
CLSID|{7632373d-4438-4d36-be59-22dc4dd85f41}
CLSIA|{a1a961da-2ba6-4032-859e-01ac35357163}
CLSIA|{ffd2825e-0785-40c5-9a41-518f53a8261
AUTST|Belt
AUTST|kkqejwjaqtb
AUTST|ntechin
AUTST|popuppers64
AUTST|satmat
AUTST|SysStart
AUTST|xqkako
AUTST|ZStart
CLASS|SiteHlpr.SiteHlprObj
CLASS|VX2.VX2Obj
RKSOF|TPS108
FILEN|%systemroot%\system32\vx0.nls
FILEN|%systemroot%\system32\vx1.nls
FILEN|%systemroot%\system32\vx1x.nls
FILEN|%systemroot%\system32\vx2.nls
FILEN|%systemroot%\system32\vx2x.nls
FILEN|%systemroot%\system32\vx3.nls
FILEN|%systemroot%\vx0.nls
FILEN|bi_prob.exe
FILEN|msview.dll
FILEN|sysvx.exe
FILEN|tps108.cab
FILEN|tps108.dll
FILEN|vx2.dll
NEWPR|630|W32.Hawawi.Worm
PRCAT|5
CLSID|{3df2ae33-26a8-11d4-bdd2-00104bfec09f}
CLASS|smtpcontrol.smtp
NEWPR|484|Wazam
PRCAT|5
CLSIA|{b5e60a66-0c51-4894-8df8-cbdf4e478d58}
NEWPR|898|WeatherScope
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Weatherscope
DIREC|%ProgramFiles%\Weatherscope
RKSOF|Gator.com\Gator\dyn\GCH\_weather
RKSOF|Gator.com\Weatherscope
RKSOF|Weatherscope
UINST|Weatherscope
FILEN|%userprofile%\desktop\WeatherscopeSetup.exe
FILEN|weatherscope website.lnk
FILEN|weatherscope.exe
FILEN|weatherscopesetup.exe
NEWPR|634|Web Behavior
PRCAT|5
CLSIA|{0054ad19-7e4e-4ae4-b275-20f237280f5c}
CLSIA|{645d793b-33e2-4175-a7e1-ba490839358a}
NEWPR|1237|Web3000
PRCAT|5
AUTST|w3knetwork
RKSOF|web3000.com
UINST|textwiz_is1
UINST|web3000 network
UINST|xtractor plus_is1
NEWPR|2525|WebBullion
PRCAT|5
RKSOF|VB and VBA Program Settings\webbullion
NEWPR|2134|Webcrawler
PRCAT|5
CLSID|{9677f3f1-e994-451f-805f-7148cc8ae040}
NEWPR|2517|WebDir
PRCAT|5
CLSID|{453dca38-2a09-4dbe-a617-a2711c8480d0}
CLSID|{c003c49f-53e4-4a72-b7d6-0b2b9997392f}
CLSID|{e7bf2c44-c0cc-4592-8349-0f899ada5447}
REGKE|HKEY_CLASSES_ROOT\AppID\webdir.DLL
CLASS|webdir.WebDirObj
NEWPR|26|WebHancer
PRCAT|5
CLSID|{c89435b0-cdfe-11d3-976a-00e02913a9e0}
CLSID|{c8cb3870-cdfe-11d3-976a-00e02913a9e0}
CLSID|{c900b400-cdfe-11d3-976a-00e02913a9e0}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\webHancer Agent
DIREC|%allusersprofile%\Start menu\Programs\WinAntiVirus Pro 2006
DIREC|%programfiles%\em\
DIREC|%programfiles%\mm\
DIREC|%programfiles%\webhancer\
DIREC|%programfiles%\whInstall\
WINDO|whAgent
AUTST|webhancer agent
AUTST|webhancer survey companion
CLASS|whiehelperobi.whiehelperobj
CLASS|whiehelperobj.whiehelperobj
RKSOF|WebHancer
RKSOF|whsurvey
UINST|webhancer agent
UINST|whsurvey
FILEN|wbhshare.dll
FILEN|webhdll.dll
FILEN|whagent.exe
FILEN|whagent_update.exe
FILEN|whcc-giant.exe
FILEN|whcc_realeuser.exe
FILEN|whiehlpr.dll
FILEN|whieshm.dll
FILEN|whinstaller.exe
FILEN|whsurvey.exe
NEWPR|769|Websearch
PRCAT|5
CLSID|{1ff04b25-0a23-4a12-960c-73f8b9950436}
CLSID|{234f09fb-fe89-4c6d-9203-31832fc051c3}
CLSID|{365b9a54-e613-46e5-9db1-4f91a9de80bd}
CLSID|{37ac49e3-e906-4bd8-ae83-d0f7fb48fd17}
CLSID|{618be527-b7f5-417c-bc51-98fdc2d6de61}
CLSID|{66c22569-f05c-4a70-a142-763b337e1002}
CLSID|{69357d4e-bf4d-4651-91e9-52ecd45a0128}
CLSID|{6e21f428-5617-47f7-aed8-b2e1d8fba711}
CLSID|{6f59d850-a155-4930-98ae-689a2bc7b8e8}
CLSID|{708be496-e202-497b-bc31-9cf47e3bf8d6}
CLSID|{7b8bd940-b1ef-460c-85a2-9acaaf7f9303}
CLSIA|{87067f04-de4c-4688-bc3c-4fcf39d609e7}
CLSIA|{886dde35-e955-11d0-a707-000000521958}
CLSID|{99aa88d1-d9d3-410a-be9e-044f94c183da}
CLSID|{af8b3c81-cd19-45fb-b6be-160d27711de8}
CLSID|{bbf122a7-8a4d-45b5-9e00-0f68bc87c904}
CLSID|{c380566d-f343-42ab-987b-6b38a1a35747}
CLSID|{cabcf5e7-0c79-4f1c-909d-b9cf68fed746}
CLSID|{cae0999f-78c5-49dc-9f30-13142aaaaba4}
CLSID|{d1951679-1d52-43fc-9585-0737143585f5}
CLSID|{d8bd4ded-5bb2-4d4e-9a6a-f10244fed7d6}
CLSID|{db9a4e78-35df-4a54-b6c5-c5190ceaf949}
CLSIA|{e4463a35-7e7a-4621-8248-91307afa8ead}
CLSID|{f1616b86-9288-489d-b71a-0ccf2f1a89da}
CLSID|{f273d4ea-2025-4410-8408-251a0cd46be7}
CLSID|{fb45c451-b0e9-4407-bb6a-9361013f3e9a}
DIREC|%ALLUSERSPROFILE%\Start Menu\ProgramsWeb Search Tools\
DIREC|%programfiles%\websearch\
AUTST|ir50_32
AUTST|Mmgsvc
AUTST|Narrator
AUTST|Pfkezr
AUTST|SAK
AUTST|TBPS
AUTST|TBPSSvc
AUTST|websearch
RKSOF|toolbar
FILEN|%programfiles%\Toolbar\tbps.dat
FILEN|edowst3.exe
FILEN|zcwedowst3.exe
NEWPR|1201|WebSecureAlert
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\WebSecureAlert\
DIREC|%ALLUSERSPROFILE%\WebSecureAlert
DIREC|%ProgramFiles%\WebSecureAlert
RKSOF|Gator.com\WebSecureAlert
RKSOF|WebSecureAlert
UINST|WebSecureAlert
FILEN|websecurealert.exe
FILEN|websecurealertsetup.exe
FILEN|websecureuninstaller.exe
FILEN|wsahelper.dll
NEWPR|2553|WebThisWebThat
PRCAT|5
DIREC|%allusersprofile%\Start Menu\Programs\wtwt\
DIREC|%ProgramFiles%\wtwt\
UINST|wtwt
NEWPR|543|Whazit
PRCAT|5
CLSID|{10955232-b671-11d7-8066-0040f6f477e4}
CLSIA|{267d5bd3-0dc2-4724-a196-7f4794fbb9eb}
CLSIA|{3b99f202-145a-4e5a-ac7b-88a36910bf5e}
CLSIA|{66f67511-2665-4c34-9e20-fac2c0954ef2}
CLSID|{c9176930-9c9f-4cba-9723-0f58c3e7ced6}
CLSIA|{ce156487-4d41-4e86-98cf-56115b9185ce}
CLSID|{d130f0d2-bcfd-4b15-a5e7-415159ef4969}
CLSID|{d5b72aed-e54a-11d6-b1b2-444553540000}
CLSIA|{d7d7004c-a763-4f8c-b0d4-55a7e017e69d}
CLSIA|{dcf0768d-ba7a-101a-b57a-0000c0c3ed5f}
CLASS|BrowserHelper.CBrowserHelper
CLASS|wharederer.Class1
RKSOF|180solutions\msbb
RKSOF|wms
UINST|redwhazit
FILEN|whattn.dll
NEWPR|2230|WhenU-BrowserToolbar
PRCAT|5
CLSID|{45e5dadb-dfdf-4fc3-a46c-dd34b6cddb38}
CLSID|{763bd795-24ae-44d7-82d8-f9a1ee799729}
CLASS|WUSE
UINST|WhenUSearchB
FILEN|%userprofile%\Local Settings\Temp\is-1PA2S.tmp
FILEN|%userprofile%\Local Settings\Temp\is-C0QLG.tmp
NEWPR|871|WhenU-ClockSync
PRCAT|5
DIREC|%programfiles%\ClockSync\
AUTST|ClockSync
UINST|ClockSync
FILEN|vvsni_sync_webinst.exe
NEWPR|18|WhenU-DesktopBar
PRCAT|5
CLSID|{20c9d850-244d-10e1-b3c1-20805e499d95}
CLSID|{711648f0-5ff5-4c81-805e-a1aedbab4951}
CLSID|{715839cd-abec-45d8-a83c-1275f2d837cd}
CLSID|{737830b7-f1f9-4bae-a8fc-1433c71bedff}
CLSID|{ba2325ed-f9eb-4830-8fce-0bc35b16969b}
CLSID|{beae14db-a12a-442d-bf77-4644e3661211}
CLSID|{c285d18d-43a2-4aef-83fb-bf280e660a97}
CLSIA|{e2f2b9d0-96b9-4b25-b90c-636ecb207d18}
CLSIA|{fc327b3f-377b-4cb7-8b61-27cd69816bc3}
CLSIA|{fee7fd53-3356-4d4d-8978-2c4ae3a7e109}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WUSE.1
DIREC|%programfiles%\VVSDL
DIREC|%programfiles%\VVSN
DIREC|%PROGRAMFILES%\WHENUSEARCH\
DIREC|%USERPROFILE%\Start Menu\Programs\WhenU
DIREC|%USERPROFILE%\Start Menu\Programs\WhenUSearch
WINDO|WhenUOffers
AUTST|SARU
AUTST|VVSN
AUTST|WhenUSearch
AUTST|WhenUSearchWHSE
CLASS|WhenU
RKSOF|WhenU
RKSOF|whenusearch
UINST|whenusearch
FILEN|%alluserprofile%\Desktop\Toolbar.lnk
FILEN|vvsn.exe
FILEN|whse_pb.min.g2inst.exe
NEWPR|2485|WhenU-FanzoneToolbar
PRCAT|5
FILEN|vvsn_fanz0110inst.exe
NEWPR|1149|WhenU-PriceBandit
PRCAT|5
AUTST|WhenUStart.exe
RKSOF|WhenUShop
UINST|whenushop
FILEN|vvsni_pbtb0100inst.exe
NEWPR|2376|WhenU-SaveNow
PRCAT|5
CLSID|{127df9b4-d75d-44a6-af78-8c3a8ceb03db}
CLSID|{43382522-a846-46f4-ac57-1f71ae6e1086}
CLSID|{572fb162-c0ba-4edf-8cff-e3846153b9b0}
CLSID|{72a836d1-bc00-43c0-a941-17960e4fb842}
CLSID|{a9aae1ab-9688-42c5-86f5-c12f6b9015ad}
CLSID|{df901432-1b9f-4f5b-9e56-301c553f9095}
REGKE|HKEY_CLASSES_ROOT\AppID\ACM.DLL
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WUSN.1
DIREC|%CommonProgramFiles%\WhenU\
DIREC|%programfiles%\savenow\
DIREC|%programfiles%\save\
DIREC|%programfiles%\VVSDL\
DIREC|%USERPROFILE%\Start Menu\Programs\WhenU\
AUTST|SaveNow
AUTST|Vicman_WhenUSave_Installer
AUTST|WhenUSave
CLASS|ACM.ACMFactory
CLASS|ACM.DLL
CLASS|WhenU.SiteSupport
CLASS|wusn
RKSOF|WhenUSave
UINST|SaveNow
UINST|WhenUSaveMsg
FILEN|saveinstcm.exe
FILEN|saveuninst.exe
FILEN|saveupdate.exe
FILEN|setupsavenow.exe
FILEN|vvsni_savenowsiteinst.exe
NEWPR|2396|WhenU-UControl
PRCAT|5
CLSID|{0a65ca2b-edb9-48b1-92da-1d92c72498e4}
CLSID|{0c4c45db-a4dc-4cf4-8f1d-8cadf97855c9}
CLSID|{28d4752f-cf84-11d1-834c-00a0249f0c28}
CLSID|{5b061650-38ae-49b4-9f5d-35396b2ceff5}
CLSID|{70271f18-b604-40fe-a8cd-15baeb11ed84}
CLSID|{8cbdba78-8cd5-4037-bd94-67cd49958d23}
CLSID|{916d4be3-6b0f-4e73-871a-17bd6ef3b2f9}
CLSID|{a001a440-e479-4fa9-8270-2cc9f0e69e2c}
CLSID|{c831c7c9-e46c-45f2-b44e-b7f72e2a9a1d}
CLSID|{cb8acef9-1085-4b47-b969-963e56aa9543}
CLSID|{f3208e7f-0e66-4f1d-bab9-ef7ec870ed24}
DIREC|%allusersprofile%\All Users\Application Data\Ucontrol\
DIREC|%CommonprogramFiles%\Ucontrol\
CLASS|UControlScanAndRemove.UControlScanner
CLASS|wss_sp_gen.Class1
CLASS|wss_sp_reg.Class1
RKSOF|Ucontrol
UINST|UControl Scan and Remove
NEWPR|2377|WhenU-WeatherCast
PRCAT|5
CLSID|{20752c25-2d97-4e6f-9ee2-94b74d202875}
CLSID|{389a5a59-1306-4389-a779-2eb9d0bc1ffb}
DIREC|%ProgramFiles%\WeatherCast\
DIREC|%USERPROFILE%\Start Menu\Programs\WeatherCast\
AUTST|WeatherCast
CLASS|WhenU.EmbedSE
RKSOF|WhenU\Weather
UINST|WeatherCast
FILEN|setupweathercast.exe
FILEN|sndbmark.dll
FILEN|weatherautocast0007.cab
FILEN|weatherautocast0018.cab
FILEN|weatherautocast0021.cab
FILEN|weatherinst.exe
FILEN|weatherinstcast0004.cab
FILEN|weatherinstcast0203.cab
FILEN|weatherinstcast1113.cab
FILEN|weatherinstibon0001.cab
FILEN|weatherinstslct0002.cab
NEWPR|2461|WhileYouSurf
PRCAT|5
UINST|While You Surf
NEWPR|2337|WhistleSoftware
PRCAT|5
CLSID|{0a88c7a6-f482-462a-8f43-f1ad8c009f50}
CLSID|{0bf6b2ca-be97-4275-8695-2
fb086be0b9b}
CLSID|{0cc38e71-6ad3-450c-8c71-50728a640b43}
CLSID|{0fbd6033-24c5-45d2-a1e5-38c46ed3b135}
CLSID|{220e39c3-b081-4719-ab1a-9a884dcbd05c}
CLSID|{27557cf1-a237-496d-8c8f-08f3844c6a8b}
CLSID|{322400d5-8fb0-45ba-8f09-0e837d57493b}
CLSID|{3fecb959-1fdd-4803-850a-ca3f2859f5ab}
CLSID|{54a770f4-d5f3-42ae-9fd5-390a6a4d85e7}
CLSID|{568f3ba7-b0e2-4a83-b8b6-319631c4622c}
CLSID|{7ea005fe-90da-4bc7-955b-9face4a2069c}
CLSID|{80e6ee09-3db1-4627-a7c9-dad7cfbdf05f}
CLSID|{8179b6d6-513d-45dc-b910-aa329a524142}
CLSID|{889395bf-f7f7-4023-b42e-6074de380ea5}
CLSID|{8d9bffc9-e027-4ea3-8ae9-8dbefed2fb93}
CLSID|{8da46338-ba81-4065-b7b9-36450e42b017}
CLSID|{92a17f40-e69b-44fa-9b8a-aaf7dbe413af}
CLSID|{930cb039-564e-4c04-b6a8-8b31bfb28347}
CLSID|{93cf2521-df05-41f4-b803-5eb17c4bb424}
CLSID|{99258154-5666-4561-ad45-c76ae7077b70}
CLSID|{9f05772f-c5ab-4491-b8e1-a5a1a0b883a7}
CLSID|{a16e4ecf-12aa-49e2-9891-ece57af678b9}
CLSID|{a58aacf2-6e0f-4465-8c81-52151e60e07b}
CLSID|{a625720f-c6eb-4806-b3d6-8fc4df89db94}
CLSID|{aa5955f9-b090-4d3b-ad7f-c9b46509bb87}
CLSID|{ac8b00eb-0b68-49a6-a278-cbba09e8151e}
CLSID|{b135ed26-a131-4861-b081-35c69398a704}
CLSID|{b8848f69-e8e2-4952-90f2-bc4ef0c22243}
CLSID|{bb46ac71-9f97-4518-b0d0-f3008b65cf88}
CLSID|{c7a2084b-969c-439a-96e8-176bf9a93879}
CLSID|{d02fac77-c2e0-44d9-aa62-e9f40831ca8e}
CLSID|{d1bcd273-d241-4bff-a2a0-e45b3b4eb27b}
CLSID|{d5e6a641-453e-4650-a49a-fa912a870827}
CLSID|{ebcf7b0e-2277-4ee4-95ee-3d542cdb8191}
CLSID|{f75448f7-4f62-45fa-9bc1-4250bb4d87c9}
CLSID|{fdc2fa83-0e09-427a-a4e6-04fb98667c32}
CLSID|{fe2c03f1-eb17-4017-9c22-99c65870b9ec}
DIREC|%ProgramFiles%\WhistleSoftware\
CLASS|IMCUpdate.Update
CLASS|ImcWselParser.WselParser
CLASS|WhistleHlprObj.WhistleHlprObj
CLASS|WselServices.WselLogServices
CLASS|WselServices.WselNetworkServices
CLASS|WselServices.WselXmlServices
CLASS|WselTypeLibrary.User
CLASS|WselTypeLibrary.WselService
CLASS|WselTypeLibrary.WselServiceCol
RKSOF|WhistleSoftware
UINST|Whistle Software
NEWPR|2058|WierdontheWeb
PRCAT|5
DIREC|%programfiles%\WeirdOnTheWeb\
AUTST|WeirdOnTheWeb
RKSOF|WeirdOnTheWeb
UINST|WeirdOnTheWeb
FILEN|%userprofile%\favorites\weirdontheweb.url
FILEN|weirdontheweb_topc.exe
NEWPR|2216|Win32.Stervis.b
PRCAT|5
SERVK|SvcProc
NEWPR|2522|Wina
PRCAT|5
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\WinA
DIREC|%ProgramFiles%\WinA\
UINST|WinA
NEWPR|796|WinAd
PRCAT|5
CLSID|{002eb272-2590-4693-b166-fbd5d9b6fea6}
CLSID|{53d3c442-8fee-4784-9a21-6297d39613f0}
DIREC|%ProgramFiles%\Winad Client
AUTST|Winad Client
AUTST|WNAD
NEWPR|2764|Winadiscount Toolbar
PRCAT|5
CLSID|{4961a993-7f48-4c50-a30e-d597ac571707}
CLSID|{4e7bd74f-2b8d-469e-87be-a334b786b339}
DIREC|%ProgramFiles%\winadiscount\
CLASS|winadiscount.WINADISCOUNT
CLASS|winadiscount.WINADISCOUNTMenu Button
CLASS|winadiscount.WINADISCOUNTToggle Button
RKSOF|winadiscount
UINST|winadiscount
NEWPR|2688|Windows AdService
PRCAT|5
DIREC|%ProgramFiles%\Windows AdService\
AUTST|Windows AdService
RKSOF|Windows AdService
UINST|Windows AdService
NEWPR|3298|Windows FastS Toolkit
PRCAT|5
CLSID|{e3231ba4-4271-402e-b20c-d5cfff70f9d4}
AUTST|fasts_on
RKSOF|fasts
UINST|fasts
NEWPR|775|Windows Search Bar
PRCAT|5
CLSID|{9fb534e3-67cb-4307-ae0a-9e8b5581be2c}
CLSID|{a1dd937d-71e1-4bb5-bd5d-1b01b9cb1c2f}
NEWPR|1148|Windupdates
PRCAT|5
CLSIA|{15ad4789-cdb4-47e1-a9da-992ee8e6bad6}
CLSIA|{15ad6789-cdb4-47e1-a9da-992ee8e6bad6}
CLSID|{962f12ae-2773-4beb-99ea-b5c3ab9a6606}
DIREC|%programfiles%\Admilli Service
DIREC|%programfiles%\AdTools Service
DIREC|%ProgramFiles%\DeskAd Service
DIREC|%programfiles%\winad client\
DIREC|%programfiles%\windows adcontrol
DIREC|%ProgramFiles%\Windows AdTools
DIREC|%ProgramFiles%\Windows ControlAd
DIREC|%ProgramFiles%\Windows ServeAd
DIREC|%programfiles%\windows taskad
DIREC|%programfiles%\windupdates\
AUTST|Admilli Service
AUTST|AdTools Service
AUTST|DeskAd Service
AUTST|Media Access
AUTST|msccrt
AUTST|qfyqakn.dll
AUTST|system spool
AUTST|Windows AdTools
AUTST|Windows ControlAd
AUTST|Windows ServeAd
AUTST|Windows TaskAd
AUTST|WindUpdates
AUTST|winform
AUTST|winupdate
AUTST|winupdtl
CLASS|AdManCtlx.Installer
CLASS|BridgeX.Installer
CLASS|MediaAccX.Installer
CLASS|WinadX.Installer
CLASS|WinStatX.Installer
RKSOF|Admilli Service
RKSOF|AdStatus Service
RKSOF|AdTools Service
RKSOF|DeskAd Service
RKSOF|Preview AdService
RKSOF|t5c
RKSOF|t5d
RKSOF|t5e
RKSOF|t5f
RKSOF|t5r
RKSOF|Windows TaskAd
RKSOF|WindUpdates
RKSOF|WinUpdt
UINST|Admilli Service
UINST|AdTools Service
UINST|DeskAd Service
UINST|Wind Updates
UINST|Windows TaskAd
FILEN|%windir%\system32\netut80ex.vxd
FILEN|%windir%\system32\winup2date.dll
FILEN|%windir%\system32\winupdt.008
FILEN|%windir%\system32\winupdt.bin
FILEN|bridge-c18.cab
FILEN|mediaaccess.exe
FILEN|mediaacck.exe
FILEN|winad.exe
FILEN|winctladshift.dll
FILEN|winka.exe
NEWPR|942|WinFavorites
PRCAT|5
CLSID|{4fdbdbad-fefe-4c4c-9cc1-1181052afb12}
CLSID|{80bb7465-a638-43b5-9827-8e8fe38dfcc1}
CLSID|{b88a3af1-4f1b-4400-8ffb-3fcb108ce115}
CLSID|{c094876d-1b0e-46fa-b6a6-7ffc0f970c27}
CLSID|{ddaf2479-6f00-4599-998a-3ed75686c6d0}
DIREC|%programfiles%\winfavorites
AUTST|oljxtggp
AUTST|WinFavorites
CLASS|bridge.brdg
RKSOF|winfavorites
UINST|win favorites
NEWPR|1712|WinFetcher
PRCAT|5
AUTST|imr1x
NEWPR|1443|Winpage
PRCAT|5
CLSID|{12df6e3e-6272-4ae8-880b-2158d60791c0}
CLSID|{c4c16842-a83e-4fc1-b9ef-995f764da9b2}
CLSID|{f31ef3c5-dabf-4258-9cb8-b11b52c94d8c}
DIREC|%ProgramFiles%\Homepage
CLASS|WinPageBHO.DLL
CLASS|WinPageBHO.WinPageIEExtension
NEWPR|624|Winpup
PRCAT|5
CLSIA|{9387b9e0-3da2-436e-88e5-fa09ae3a48c0}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\pup
AUTST|asauthr
AUTST|dhcpv
AUTST|dwwizh
AUTST|qlsrv32s
AUTST|svidc32m
AUTST|win32app
CLASS|pup.setup
RKSOF|pup
NEWPR|609|Winshow
PRCAT|5
CLSIA|{6cc1c918-ae8b-4373-a5b4-28ba1851e39a}
DIREC|%APPDATA%\winshow\
CLASS|WinShow.ViewSource
RKSOF|WinShow
FILEN|msupdater.exe
FILEN|winshow.dll
NEWPR|1136|Winspoe
PRCAT|5
CLSID|{043b5d00-92a9-4cae-a3d8-a4b4b8d52bb1}
NEWPR|2352|Winsync
PRCAT|5
CLSID|{6ec11407-5b2e-4e25-8bdf-77445b52ab37}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\woualo
UINST|WebNexus
FILEN|mynexus.exe
FILEN|webnexus.exe
NEWPR|1784|WishBone
PRCAT|5
CLSID|{08e62c6d-babd-4be9-a015-ecfe9cc76997}
CLSID|{10cd7efc-7d1a-4599-ab49-9249c714b87c}
CLSIA|{3aa90bc2-58c0-4f4d-a87c-2c6f3d3cd5fe}
CLSID|{40930a0f-68cc-4b81-848a-77a78f85fa7b}
CLSID|{4fd85670-606a-42e9-bba5-2bc63493b677}
CLSID|{86f4ad51-ee90-409d-944b-fdb0c939b41c}
CLSID|{87b1e57c-ff70-4c69-9ce8-57cb8f67aba8}
CLSID|{aeef5ccc-71c7-4053-88a4-6cb87fd4e461}
CLSID|{b004262d-5762-4daa-a222-3b9a738c83ea}
CLSID|{b0931261-03c3-4bb3-9ce1-22bfda3af445}
CLSID|{b6ce642a-2171-4661-bb46-aed01c2ed9ec}
CLSID|{c331bd6e-06ab-41a0-b95f-d7ca379aceaa}
CLSID|{cc4a4cd1-e441-4a03-941c-e183bce357e7}
CLSID|{da3db988-d1fb-4919-a684-78e6a5358340}
CLSID|{db2e7bc7-104f-42b5-aae3-921e3057db06}
CLSID|{eaa87376-c391-494e-9da2-2bd9c798e54f}
DIREC|%WINdir%\system32\WBM\
CLASS|Gigel.ScriptCallback
CLASS|Keys.KeyWords
CLASS|MenuContainer.MenuHolder
CLASS|MenuContainer.RegAcess
CLASS|MenuContainer.WebSink
CLASS|MicroInstaller.WBMInstaller
CLASS|WBM.AtlBrCon
CLASS|WBM.ExplorerBar
CLASS|WBM.WebMonitor
CLASS|Wbmbar.ViewSource
CLASS|Wbmbar.WBMToolBar
RKSOF|WBInstaller
RKSOF|WBM
RKSOF|Wishbone Media
UINST|WBInstaller
NEWPR|29|WNAD
PRCAT|5
FILEN|wnad-update.exe
FILEN|wnad.exe
NEWPR|1713|Wotch
PRCAT|5
AUTST|media_manager
AUTST|media_stub
NEWPR|483|WurldMedia
PRCAT|5
CLSID|{01fb9c55-fc66-4476-a199-389241193188}
CLSIA|{1b80440d-b4c0-49d7-8d2f-77f16777629b}
CLSIA|{2737a6c0-7e24-11d7-b299-00e0297e0844}
CLSIA|{3a279869-c6b6-4410-a041-0435de6ad916}
CLSIA|{40ac4d2d-491d-11d4-aaf2-0008c75dcd2b}
CLSID|{48f35889-7f47-4a93-8876-7ab20324e5d7}
CLSID|{525bbd23-1863-46c6-86d6-5f9a3715d44e}
CLSIA|{5a3a5040-4210-11d7-bd2e-00080e34122f}
CLSIA|{6270dfc1-edfb-4bc4-be8c-842740ba290b}
CLSIA|{8a880893-e6b2-4c29-b168-181a4ef6b852}
CLSID|{8e9c4f32-bd3f-4c49-9af5-3f4c5d32ebd7}
CLSIA|{98d7b53e-b1d2-4755-b0a4-703e18ff91e8}
CLSID|{a83e42b1-1ae7-4ce6-b128-ab0f4a126b2c}
CLSIA|{bfbae8da-9920-4166-a5a4-ebd03f59abf5}
CLSIA|{cdbcfeae-10ba-482c-9f6e-fc67207082d8}
CLSIA|{d14641fa-445b-448e-9994-209f7af15641}
CLSIA|{f325e940-45ee-11d7-a420-444553540000}
CLASS|Mobho.IEHlprObj
CLASS|Tchk.TChkBHO
RKSOF|morp
RKSOF|rdxr
FILEN|bpboh.dll
FILEN|m030106shop.dll
NEWPR|2933|X Password Manager
PRCAT|5
DIREC|%ProgramFiles%\X Password Manager\
DIREC|%userprofile%\Start Menu\Programs\X Password Manager\
UINST|X Password Manager
FILEN|%userprofile%\Desktop\X Password Manager.lnk
NEWPR|2702|Xagon - Atomic Mp3 Finder
PRCAT|5
DIREC|%ProgramFiles%\Xagon\
RKSOF|Xagon
UINST|Atomic Mp3 Finder
NEWPR|2587|Xbarre
PRCAT|5
CLSID|{4e7bd74f-2b8d-469e-d7ec-ed6db68dfa7d}
CLSID|{4e7bd74f-2b8d-469e-d7ec-ed6db68dfa7e}
CLSID|{4e7bd74f-2b8d-469e-d7ec-ed6db68dfa7f}
DIREC|%ProgramFiles%\xbarre\
CLASS|xbarre.XBARRE
CLASS|xbarre.XBARREMenu Button
CLASS|xbarre.XBARREToggle Button
RKSOF|XBARRE
UINST|XBARRE
NEWPR|1828|Xhrmy
PRCAT|5
AUTST|xhrmy
RKSOF|Xhrmy
NEWPR|1220|Xlocator/Winlocator
PRCAT|5
CLSIA|{121ac498-3f3a-4c39-9bea-cfc4ea809fdf}
CLSID|{89aeab46-8e8a-4045-9003-5614bfbfe90b}
CLSID|{8f0d6eed-bc11-4e7f-8276-9748947e4a50}
AUTST|winlocatorupdate
CLASS|WinLocator.Portal
CLASS|WinLocatorHelper.bho
CLASS|XlocatorInstall.Install
RKSOF|winlocator
FILEN|%WINdir%/winlocator.reg
NEWPR|1234|Xrenoder
PRCAT|5
UINST|AutoUpdate
NEWPR|430|Xupiter
PRCAT|5
CLSID|{07fa131e-2eb2-446f-93d2-9f877320010b}
CLSID|{1348e05a-21c7-4134-b4a4-3c12234fca3f}
CLSID|{1a8b567b-bd3f-44a1-8b94-f50d37a1914e}
CLSID|{2662bdd7-05d6-408f-b241-ff98face6054}
CLSIA|{280168bc-76bf-4cd0-b835-3d686efa8ddc}
CLSID|{29089b98-af05-4769-b627-86a745d4b672}
CLSID|{3a021d2f-5f75-47f5-9bab-a137e1fb015f}
CLSIA|{3c5ba506-6c30-4738-9ced-797acadea8dc}
CLSID|{3f4386e5-2fbe-44a8-81cf-4b792490605f}
CLSID|{43732063-1bda-45a0-bbee-13e014cb4041}
CLSID|{43f1b4ad-92ef-4db3-bda9-12335b012dd0}
CLSID|{4a0f42b7-a61b-4131-bf41-bf05a2635bfd}
CLSID|{55b201ff-c057-e521-6d17-0489b6cf9930}
CLSIA|{57e69d5a-6539-4d7d-9637-775de8a385b4}
CLSID|{6e6dd93e-1fc3-4f43-8afb-1b7b90c9d3eb}
CLSIA|{702ad576-fddb-4d0f-9811-a43252064684}
CLSID|{74232635-a013-49f2-b869-1b1ab932d944}
CLSID|{7f0f5d9a-84cb-11d4-8137-00500487b1c5}
CLSID|{7f0f5da6-84cb-11d4-8137-00500487b1c5}
CLSID|{83b027c5-1489-4ec5-a290-47da8058ac04}
CLSID|{899be974-d575-48bb-a9c7-1d24e8042be4}
CLSID|{8bee173b-c006-4f0e-acd2-84a882bebcff}
CLSID|{909e0059-f545-42de-9d2c-cc4a3e336ec3}
CLSID|{910e67a6-bd53-46df-8434-41498b7d22f7}
CLSID|{9464c98e-b5f1-4c6a-bd3f-9696e3bd081e}
CLSID|{9dbdd71c-0a7f-48ac-9ffa-e102b3750b9d}
CLSIA|{a27cfcae-9351-4d74-bffc-21eb19693d8c}
CLSID|{b0db6360-8d7f-11d4-8137-00500487b1c5}
CLSID|{bf986691-7f7b-4f94-85e0-20e75350701f}
CLSID|{bfa2c963-fc24-4770-8c19-0d5a1cd58df9}
CLSID|{c09fb84d-b9ed-43eb-afed-f145c26cb839}
CLSID|{c0cad17e-00a3-4f40-9015-d569c3114ba3}
CLSID|{c2e56e18-2f04-4ab9-9333-b2db3c350956}
CLSID|{c6c2871f-7467-4a35-90fa-9e9894bc1916}
CLSID|{c81b4b57-b06b-409d-aed0-028051683796}
CLSID|{ce2eab19-e31d-43ca-a860-f95a2ca50040}
CLSIA|{d48f2e28-68e2-4920-9848-d6e6c7ab3eb7}
CLSID|{d686db39-659a-491a-a35c-60b99495c16e}
CLSIA|{d7b3e460-9968-4191-bd6f-beed1bc18482}
CLSID|{e9cbbeed-20b6-456c-8589-cf364d9d2370}
CLSID|{eb07a6d3-8e36-11d4-8138-00500487b1c5}
CLSID|{f8c5ea77-7d72-405c-b90a-093655b0f544}
CLSID|{ffe56921-248b-4c75-9eee-01706310e371}
DIREC|%programfiles%\Sqwire\
DIREC|%programfiles%\Xupiter\
AUTST|buwhtje.dll
AUTST|xupitercfgloader
AUTST|XupiterStartup
CLASS|xtsearch.xtsearchhook
CLASS|xtupdate.xt
CLASS|xupitertoolbar.band
RKSOF|Xupiter
UINST|Xupiter
FILEN|bobsaver.exe
FILEN|bobsaver.scr
FILEN|oeloader.dll
FILEN|popunder.exe
FILEN|tsl_rc0.dll
FILEN|xtcfgloader.exe
FILEN|xtcfgrunner.exe
FILEN|xtsearch.dll
FILEN|xtupdate.dll
FILEN|xupiterstartup.exe
FILEN|xupiterstartup2003.exe
FILEN|xupitertoolbar.dll
FILEN|xupitertoolbarinstaller.exe
FILEN|xupitertoolbarloader.cab
FILEN|xupitertoolbarloader.exe
FILEN|xupiterwauninstaller.exe
NEWPR|2426|Xware
PRCAT|5
CLSIA|{42b1c70d-9823-41f7-810a-682da294d868}
AUTST|sload
AUTST|xware
IEZON|xxsware.com
NEWPR|610|xxxtoolbar
PRCAT|5
CLSIA|{386a771c-e96a-421f-8ba7-32f1b706892f}
CLSIA|{4418dd4d-7265-4c32-bc0a-3fdb3c2da938}
CLSIA|{ef86873f-04c2-4a95-a373-5703c08efc7b}
IEZON|*.offshoreclicks.com
IEZON|.teensguru.com
IEZON|xxxtoolbar.com
FILEN|best.exe
NEWPR|2848|Yapbrowser
PRCAT|5
DIREC|%allusersprofile%\Start Menu\Programs\YapBrowser
DIREC|%programfiles%\yapbrowser
UINST|yapbrowser
FILEN|%allusersprofile%\Desktop\YapBrowser.lnk
FILEN|%allusersprofile%\Start Menu\Programs\Startup\YapBrowser.lnk
NEWPR|3056|Yazzle Cowabanga
PRCAT|5
DIREC|%ProgramFiles%\Cowabanga\
RKSOF|Cowabanga
UINST|Cowabanga
UINST|Yazzle1264Oin
FILEN|%USERPROFILE%\Start Menu\Programs\Games\Cowabanga.lnk
FILEN|yazzle1119oinuninstaller.exe
FILEN|yazzle1264oinadmin.exe
FILEN|yazzle1264oinuninstaller.exe
FILEN|yazzlebundle-1264.exe
NEWPR|2897|Yazzle Snow Ball War
PRCAT|5
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Yazzle Snowball Wars
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Yazzle Snowball Wars
DIREC|%programfiles%\snowball wars
DIREC|%ProgramFiles%\Yazzle Snowball Wars\
DIREC|%userprofile%\Start Menu\Programs\Yazzle Snowball Wars\
AUTST|Snowball Wars
RKSOF|Yazzle Snowball Wars
UINST|Snowball Wars
UINST|Yazzle Snowball Wars
NEWPR|2355|Yazzle Sudoku
PRCAT|5
CLSID|{665ac8e7-8b9b-40d9-a24d-c134052b6168}
CLSID|{8b7cd17e-428b-4ee7-bbcd-21875fa05d7f}
CLSID|{907977fb-8835-483f-9979-ae3101dd3d17}
CLSID|{95b10d86-f27f-40b6-9a57-53db278546d0}
CLSID|{95c2547b-0785-4278-9aea-ce65d78d853d}
REGKE|HKEY_CLASSES_ROOT\YazzleSudokuGame
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Yazzle Sudoku
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\YazzleSudokuGame
DIREC|%ProgramFiles%\Yazzle Sudoku\
DIREC|%userprofile%\Start Menu\Programs\Yazzle Sudoku\
AUTST|FT_SilentSudokuInstaller.exe
AUTST|ms05447449-1862
AUTST|sys02862447449-1
CLASS|.sdu
CLASS|YazzleSudokuGame
RKSOF|Tanw
RKSOF|Yazzle Sudoku
UINST|Y1123Oin
UINST|Y1304Oin
UINST|Yazzle1162Oin
UINST|Yazzle1438Oin
UINST|Yazzle1452Oin
UINST|YazzleSudoku
FILEN|ageu_silentsudokuinstaller.exe
FILEN|ageu_sudokuinstaller.exe
FILEN|ft_silentsudokuinstaller.exe
FILEN|gs_silentsudokuinstaller.exe
FILEN|yazzle1119oinadmin.exe
FILEN|yazzlebundle-1119.exe
FILEN|yazzlebundle-1304.exe
FILEN|yazzlebundle-1438.exe
FILEN|yazzlebundle-1452.exe
NEWPR|1285|YellowPages
PRCAT|5
CLSID|{47fe5d70-9aa2-40f1-9c6b-12a255f085ea}
CLSID|{49f2248d-1734-4b0f-a7b8-542e526ee07c}
CLSID|{679695bc-a811-4a9d-8cdf-ba8c795f261a}
CLSID|{d797ad6c-6447-4db4-91d0-090344408e72}
CLASS|YellowPages.YellowBar
NEWPR|2395|Youcouldwinthis
PRCAT|5
CLSID|{d7950ab4-67f5-458e-a37d-9f2de7f250ac}
DIREC|%ProgramFiles%\YOUCOULDWINTHIS\
CLASS|AdCom.AdCom
UINST|{534902F9-3758-4304-BFC0-24800B4E5FB9}
NEWPR|3063|Your Screen
PRCAT|5
DIREC|%programfiles%\freeze.com
DIREC|%programfiles%\yourscreen
CLASS|Freeze.DesktopManager.BrowserHelper.DLL
CLASS|FreezeDesktopManagerBrowserHel.Browse
CLASS|FreezeDesktopManagerBrowserHel.BrowserH
RKSOF|Freeze
UINST|Living Waterfalls Wallpaper #1
UINST|YourScreen
FILEN|waterfalls1awfree.exe
FILEN|yourscreen_4_pch.exe
NEWPR|974|YourSiteBar
PRCAT|5
CLSID|{03b800f9-2536-4441-8cda-2a3e6d15b4f8}
CLSIA|{42f2c9ba-614f-47c0-b3e3-ecfd34eed658}
CLSID|{4ee12b71-aa5e-45ec-8666-2db3ad3fdf44}
CLSIA|{771a1334-6b08-4a6b-aedc-cf994ba2cebe}
CLSID|{bf06da8e-2beb-4816-9bbd-f7625246e245}
CLSID|{db447818-96b4-40df-8a55-720da496f514}
CLSID|{dfbcc1eb-b149-487e-80c1-cc1562021542}
DIREC|%programfiles%\YourSiteBar
DIREC|%programfiles%\YourSitetoolbar
CLASS|Ysb.YsbObj
CLASS|YSBactivex.Installer
RKSOF|YourSiteBar
UINST|YourSiteBar
FILEN|yoursitebar.exe
NEWPR|795|Zamingo
PRCAT|5
AUTST|Adstartup
FILEN|adstartup.exe
FILEN|ieenhancer.dll
NEWPR|1987|Zango
PRCAT|5
CLSIA|{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8}
CLSIA|{99410cde-6f16-42ce-9d49-3807f78f0287}
CLSID|{d28cd14c-50be-4cfa-951e-b37f25da3472}
CLSIA|{deceaaa2-370a-49bb-9362-68c3a58ddc62}
CLSID|{ea0d26bd-9029-431a-86e0-83152d67828a}
DIREC|%allusersprofile%\Start Menu\Programs\Zango Games\
DIREC|%programfiles%\Zango Games\
DIREC|%programfiles%\ZangoClient\
DIREC|%programfiles%\zango\
DIREC|%userprofile%\Start Menu\Programs\Zango Games\
DIREC|%userprofile%\Start Menu\Programs\Zango\
CLASS|ncmyb.SABHO
CLASS|saix.installercaller
RKSOF|zanu
UINST|zanu
FILEN|%programfiles%\zango\zango.exe
FILEN|zango.exe
FILEN|zangoinstaller.dll
FILEN|zangoinstaller.exe
FILEN|zangolib.dll
FILEN|zangomuncher.exe
FILEN|zanuhook.dll
NEWPR|2373|Zango Grab&Burn
PRCAT|5
DIREC|%programfiles%\Zango Applications\
DIREC|%userprofile%\Start Menu\Programs\Zango Applications\
RKSOF|www.zango
UINST|Zango Grab & Burn
UINST|Zango Grab & Burn DisplayIcon
FILEN|%userprofile%\desktop\Zango Grab & Burn.lnk
NEWPR|2176|Zango Messenger
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\Zango
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\Zango Applications
DIREC|%programfiles%\Zango Applications
AUTST|zanu
RKSOF|Zango Messenger
UINST|Zango Messenger
NEWPR|2568|Zango Times
PRCAT|5
DIREC|%appdata%\Zango TvTimes\
UINST|Zango TV Times
NEWPR|2298|Zango Toolbar
PRCAT|5
CLSID|{01bf19c2-59d3-43e9-a2cc-c2d62d8878d3}
CLSID|{f1f040d5-e8f8-4680-b101-9334e9773841}
REGKE|HKEY_CLASSES_ROOT\AppID\ZangoToolbar.DLL
DIREC|%allusersprofile%\Start Menu\Programs\Zango\
DIREC|%programfiles%\Zango Programs\
DIREC|%ProgramFiles%\Zango Toolbar\
AUTST|zango
CLASS|ZangoToolbar.DLL
CLASS|ZangoToolbar.ZCToolBand
RKSOF|zango
RKSOF|Zango Programs
UINST|zango
UINST|Zango Toolbar
FILEN|zangohook.dll
FILEN|zangotb.dll
FILEN|zangotbuninstaller.exe
NEWPR|2902|Zango TV
PRCAT|5
CLSID|{5490ef03-553e-42d6-a437-9bfb70c45231}
DIREC|%allusersprofile%\Start Menu\Programs\Zango Programs\
DIREC|%allusersprofile%\Start Menu\Programs\Zango Programs\Zango TV\
DIREC|%ProgramFiles%\Zango Programs\Zango TV\
DIREC|%systemdrive%\WINNT\Installer\{5490EF03-553E-42D6-A437-9BFB70C45231}\
FILEN|%
allusersprofile%\Desktop\Zango TV.lnk
NEWPR|2573|Zango-AirHockey
PRCAT|5
DIREC|%allusersprofile%\Local Settings\Temp\Zango\AirHockey\
DIREC|%allusersprofile%\Start Menu\Programs\Zango Games\Air Hockey\
DIREC|%ProgramFiles%\Zango Games\AirHockey\
RKSOF|MLP\AirHockey
UINST|Air Hockey
NEWPR|2567|Zango-Astrology
PRCAT|5
DIREC|%appdata%\Zango Astrology\
UINST|Zango Astrology
NEWPR|2556|Zango-Checkers
PRCAT|5
NEWPR|2532|Zango-Chess
PRCAT|5
DIREC|%allusersprofile%\Start Menu\Programs\Zango Games\Chess\
DIREC|%ProgramFiles%\Zango Games\Chess\
UINST|Chess
NEWPR|2540|Zango-DavidvsGoliath
PRCAT|5
NEWPR|2577|Zango-Foosball
PRCAT|5
DIREC|%allusersprofile%\Local Settings\Temp\Zango\
DIREC|%allusersprofile%\Start Menu\Programs\Zango Games\Foosball\
DIREC|%ProgramFiles%\Zango Games\Foosball\
RKSOF|Lantern Games\GameRoom\Foosball
UINST|Foosball
NEWPR|2338|Zango-JadeShadow
PRCAT|5
FILEN|jadeshadowinstall.exe
FILEN|jadeshadowsetup.exe
NEWPR|2559|Zango-Libraryoftheages
PRCAT|5
UINST|Library of the Ages
NEWPR|2566|Zango-MovieTimes
PRCAT|5
CLSID|{56f1d444-11bf-4879-a12b-79cf0177f038}
DIREC|%appdata%\Zango MovieTimes\
CLASS|ClientAX.ZangoClientAX
CLASS|zangohook.SABHO
UINST|Zango Movie Times
NEWPR|2570|Zango-Muncher
PRCAT|5
UINST|Zango Muncher
NEWPR|2563|Zango-SecretChamber
PRCAT|5
UINST|Secret Chamber
NEWPR|2558|Zango-Shuffleboard
PRCAT|5
UINST|Shuffle Board
NEWPR|2543|Zango-Solitaire
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\Zango Games\Zango Solitaire\
DIREC|%ProgramFiles%\Zango Games\Zango Solitaire\
UINST|Zango Solitaire
NEWPR|2598|Zango-WallsofJericho
PRCAT|5
UINST|Walls of Jericho
NEWPR|2497|Zango-Windwords
PRCAT|5
DIREC|%ALLUSERSPROFILE%\Start Menu\Programs\Zango Games\Wind Words\
DIREC|%ProgramFiles%\Zango Games\Wind Words\
UINST|Wind Words
NEWPR|1714|ZapSpot
PRCAT|5
DIREC|%APPDATA%\Application Data\ZapSpot\
DIREC|%USERPROFILE%\My Documents\My ZapSpot\
CLASS|ZapSpot.ZML
FILEN|zapspot.exe
NEWPR|2791|Zeno Search Assistant
PRCAT|5
AUTST|BrowserUpdateSched
AUTST|ExploreUpdSched
AUTST|{2F-F8-82-28-ZN}
AUTST|{E4-44-4B-B0-ZN}
UINST|Enhanced Ads by Zeno
UINST|Zeno Search Assistant
FILEN|%userprofile%\Start Menu\Programs\Startup\Zeno.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\Startup\Z_Start.lnk
FILEN|%windir%\system32\msnav32.ax
FILEN|dwdsregt.exe
FILEN|nt68rrtc12.sys
FILEN|zicorn001.exe
NEWPR|2359|ZeroPopUp Toolbar
PRCAT|5
DIREC|%programfiles%\ZeroPopupBar\
CLASS|ToolBand.ToolBandObj
UINST|ZeroPopUpBar
NEWPR|957|ZestyFind
PRCAT|5
CLSID|{5cf8a355-f8c6-4883-9c25-49d01a7d25be}
CLSID|{86227d9c-0efe-4f8a-aa55-30386a3f5686}
CLSIA|{a16e6189-a1dd-4696-9806-0324c145d794}
CLSIA|{ca034dcc-a580-4333-b52f-15f98c42e04c}
CLSIA|{fe4bbea8-1efd-4b8a-bd1b-341ccdbeeaa6}
DIREC|%ProgramFiles%\YourSiteBar\
AUTST|Findwavemeetloud
AUTST|gdaj
AUTST|kvern16.dll
AUTST|Trans Comp
AUTST|vernn16.dll
FILEN|%USERPROFILE%\desktop\Cheap Holiday Travel.url
FILEN|%USERPROFILE%\desktop\Free Online Music.url
FILEN|icont.exe
NEWPR|2001|Zeta
PRCAT|5
REGKE|HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZESOFT
REGKE|HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ZESOFT
DIREC|%windir%\system32\jcngn
DIREC|%windir%\system32\omjffbrq
DIREC|%windir%\system32\qkoj
DIREC|%windir%\system32\yjtgnqsu
AUTST|Gmedia2
AUTST|nfxpbvd
AUTST|spiven
FILEN|%windir%\system32\spiven.exe
SERVI|nfxpbvdjcngn
SERVI|Zesoft
NEWPR|3443|Zhong
PRCAT|5
CLSID|{0cb66ba8-5e1f-4963-93d1-e1d6b78fe9a2}
CLSID|{2a0176fe-008b-4706-90f5-bba532a49731}
CLSID|{3ce496d1-1746-41cd-9489-3c0b93df10e2}
CLSID|{42d25f15-cf07-4a72-b191-db0792bf310c}
CLSID|{967a494a-6aec-4555-9caf-fa6eb00acf91}
CLSID|{9692be2f-eb8f-49d9-a11c-c24c1ef734d5}
CLSID|{a8954909-1f0f-41a5-a7fa-3b376d69e226}
CLSID|{d0903a3b-f0ea-434a-9742-98c5335c7946}
NEWPR|692|ZipClix
PRCAT|5
CLSIA|{319a68db-06d0-46da-9f93-a810d5a70836}
CLSID|{bbcd25c8-a31e-4dfb-b204-b54bba477b23}
CLSID|{ec34a4b3-809a-4a71-88d4-55b5183d6041}
DIREC|%programfiles%\zipclix\
CLASS|zipclix
CLASS|zipclixobj.zipclixobj
RKSOF|zipclix
UINST|zipclix
FILEN|zipclix.dll
FILEN|zipclix.exe
NEWPR|921|Zippylookup
PRCAT|5
CLSID|{19e41a2d-bd9d-48bb-9576-27b2cf0877c0}
CLSID|{49256fe8-6394-4ace-939c-22f35ca042ad}
NEWPR|2857|Zone-DL.Plugin
PRCAT|5
CLSIA|{2473bf2d-ca0a-11da-88db-0050bf2938e1}
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , dns-look-up.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , netbios-wait.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , netsearchsoft.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.dns-look-up.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.netbios-wait.com
REGKE|HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow , www.netsearchsoft.com
DIREC|%programfiles%\Download Plugin\
WINDO|windWWAA
WINDO|wwBYAwnd
AUTST|close jump
CLASS|DownloadPlugin.DLPlugin
UINST|Download Plugin (ActiveX)
UINST|Wait long soft
FILEN|axdlplug-1.5.0.0-0281-setup.exe
FILEN|axdlplug-1.5.0.0-147-setup.exe
FILEN|npdlplug-1.5.0.0-147-setup.exe
NEWPR|1757|Zoombar
PRCAT|5
NEWPR|1342|Zserv
PRCAT|5
CLSID|{00000000-c1ec-0345-6ec2-4d0300000000}
NEWPR|2276|ZToolbar
PRCAT|5
CLSID|{a55c3ba7-db1e-4652-867e-055ceafe8018}
CLSID|{ef77d50b-5767-4e0e-a3a4-098670025f1d}
CLSID|{fff5092f-7172-4018-827b-fa5868fb0478}
CLASS|Ztoolbar
CLASS|ZToolbar.activator
CLASS|ZToolbar.ParamWr
CLASS|ZToolbar.StockBar
RKSOF|ZsearchCo
FILEN|%windir%\blank.mht
FILEN|%windir%\system32\ztoolbar.bmp
FILEN|%windir%\system32\ztoolbar.xml
NEWPR|1119|Zuvio
PRCAT|5
CLSID|{30a56549-9d5b-4d34-afa7-440a7f0538a9}
CLSIA|{419cc403-e9fc-4c90-bbe6-c8ea9159e49d}
CLSIA|{ed2e4bb5-60ea-4624-9de2-998e441c699b}
DIREC|%ProgramFiles%\Open Site
AUTST|Open Site
CLASS|OpenSite.opensite_install
UINST|Open Site
FILEN|%systemdrive%\msole32.exe
FILEN|opensite.cab
FILEN|opensite.exe
FILEN|opensite.ocx
NEWPR|1715|ZyncosSpace
PRCAT|5
CLSID|{f0dc0cfe-d11a-489b-84c0-63748afaabf3}
DIREC|%programfiles%\zyncosspace\
AUTST|ZyncosMark
CLASS|CMCTL.CBrowserExt
CLASS|CMCTL.CURLTriggerProxy
RKSOF|Tmsitech
NEWPR|647|764 Dialer
PRCAT|8
NEWPR|956|7AdPower Dialer
PRCAT|8
CLSIA|{00000000-0000-0000-0000-000020030000}
CLSIA|{00000000-0000-0000-0000-000020040000}
CLSIA|{042eea26-2402-4e5a-b5bb-0fb445a5526e}
CLSIA|{0fcd5a05-bcec-4bb1-9ed3-88c289d87abb}
CLSIA|{2517f764-6f60-4add-8fcf-137e5b220ff6}
CLSIA|{261ee805-4893-45a3-8e9e-ad90914cb39a}
CLSIA|{35f59c80-c1f2-4eea-9981-686c7d5a9277}
CLSIA|{3b623d23-2757-4881-a01e-d560ebca5307}
CLSID|{3da4a3a4-06be-49e0-b8ba-03580903122b}
CLSIA|{4208564c-62f0-45e6-87de-0861d11c0613}
CLSIA|{4ae9e3bf-409d-4f61-9804-920968603919}
CLSIA|{4ef86fae-4fda-4b1a-a80f-811e0a5da08a}
CLSID|{5d647e9c-6b37-4636-9a78-dadb1eb93bdf}
CLSIA|{60efc337-15c2-4369-b2a0-3429b071d8b8}
CLSIA|{683dff0f-331f-44d2-b69b-46d7bfb58f32}
CLSIA|{706f3805-27d7-478d-80e5-e25d2bb030b3}
CLSIA|{8701e3b9-dc63-440b-83a1-80f27a4fcafa}
CLSIA|{8bea0789-fe58-4753-8a75-432fcd1a5705}
CLSIA|{970bf476-3cf2-4572-9ef9-4479e1591db8}
CLSIA|{9e98e84c-79e1-49c3-82eb-798fcd552efb}
CLSID|{ac86f549-28a6-4ac8-9c2c-0d52b4b1f5ec}
CLSIA|{ad0b8220-7da4-4c0a-8532-b25a9f631d3d}
CLSIA|{b1b7606a-d7b9-42a8-afa2-476308413211}
CLSIA|{bd092cd7-aa66-4ff6-8ce1-d4e01489ed2b}
CLSIA|{c7384a94-12ab-4798-9a63-67a9b24c993d}
CLSIA|{cdcbe0f1-d13a-4f86-a963-3a272d3aba7e}
CLSIA|{f1051f05-fbfa-48bd-8e45-f5d3bdc45d3d}
CLSIA|{f164ece9-e6df-4085-961c-083bd1809319}
CLSID|{f43e6264-7da7-45af-a90d-75534f0c6754}
CLSIA|{f9deab0b-ff3e-4d99-8698-9b535d164256}
CLSIA|{ffff0001-0002-101a-a3c9-08002b2f49fb}
CLSIA|{ffff0021-0002-101a-a3c9-08002b2f49fb}
AUTST|AdPopup
AUTST|AdUpdater
CLASS|VacPro.internazionale_ver11
CLASS|Vacpro.netherland_ver2
FILEN|internazionale_ver15.cab
NEWPR|2585|Absolu-trans
PRCAT|8
FILEN|absolu-trans.exe
NEWPR|583|AccessPlugin
PRCAT|8
CLSIA|{034cc2dc-3245-4b26-b5c7-7b8777739cb7}
CLSIA|{2b3ac84b-3128-45b4-bb8d-6cc9a42d24ec}
CLSIA|{42f2d240-b23c-11d6-8c73-70a05dc10000}
CLSIA|{d8efadf1-9009-11d6-8c73-608c5dc19089}
REGKE|HKEY_CLASSES_ROOT\AppID\exengd.EXE
CLASS|Exengd.DialerCon
RKSOF|DCon
RKSOF|webdialer
NEWPR|648|Aconti
PRCAT|8
CLSIA|{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}
CLSIA|{7589eee6-e336-11d4-8a7e-ee1d971d9b47}
AUTST|runwin32
CLASS|AcontiXControl
RKSOF|ALifestyle
FILEN|int179663.exe
NEWPR|2167|Active-X Dialer
PRCAT|8
CLSIA|{0f7bd988-96a9-4505-9997-19011055f07c}
CLSIA|{33bcb2bb-173d-163b-779b-33c13379504c}
CLSIA|{62c9173e-c4c3-43b9-82f2-3ddd51663b00}
CLSIA|{7dbfda8e-d33b-11d4-9269-00600868e56e}
CLSIA|{84b40160-54e0-4d2f-ac18-a6d31a9ac732}
CLSIA|{86eef11e-ff16-48ce-b1a2-474b663041a9}
CLSIA|{c56ce781-a6fc-4706-8b32-6eb4622155df}
CLSID|{cfbc1c51-d33c-11d4-9269-00600868e56e}
FILEN|gdnus208.exe
NEWPR|2575|Adh1_sexarea
PRCAT|8
DIREC|%programfiles%\montorgueil
DIREC|%userprofile%\Start Menu\Programs\HOT Dialer\
FILEN|%userprofile%\Start Menu\Latinas.lnk
NEWPR|1100|Adpower.b
PRCAT|8
CLSIA|{3e339d3c-4b12-4e8c-a529-9cc4beeafd4f}
CLSID|{7b6ff147-4e5a-4a2f-8789-84efc132849d}
CLSIA|{84bf9dc5-7bc8-4efd-
85b3-489c714f4fd1}
CLSIA|{91b9979b-c663-43a0-855e-df04025eb0a2}
CLSIA|{9ae283a5-df43-4c83-b6aa-7ebdbdb0204a}
CLSID|{e4870a7b-6c2f-42b9-9938-f6d729afc493}
CLSIA|{fbc59f54-80a2-4df5-a0ad-b2d3221c8b32}
RKSOF|ADPower
NEWPR|646|Adult Chat Dialer
PRCAT|8
CLSID|{022850cb-74fd-486d-8b1c-573ecfd599ad}
CLSIA|{2c1651ef-8827-11d6-91a2-00e02964e8e3}
CLSIA|{469843dd-ebb3-4661-b0a6-e6fe590240c9}
CLSIA|{6986a6cf-9d58-11d6-91c2-00e02964e8e3}
CLSIA|{8522f9b3-38c5-4aa4-ae40-7401f1bbc898}
CLSIA|{9dbafccf-592f-ffff-ffff-00608cec297c}
CLSID|{b5dd9a64-5c4b-4a48-be56-97c1a8f85708}
CLSIA|{ffff0017-0001-101a-a3c9-08002b2f49fb}
DIREC|%programfiles%\nog\
AUTST|addot.exe
AUTST|Lisa
AUTST|MSStartOptimizer
AUTST|RegCompres
AUTST|tibs3
CLASS|.htnw
CLASS|htnw File
RKSOF|nog
RKSOF|Pinfo
UINST|Lisa
FILEN|adult_chat.exe
FILEN|tibs3.exe
NEWPR|1971|Adult Dialer
PRCAT|8
CLSIA|{8f24de00-0d66-4f93-9405-3f21e97aee99}
CLSIA|{94118c19-b178-4e43-bbe8-0efdbb391bdb}
AUTST|HotSexy_Now
FILEN|esbadultinstaller.ocx
NEWPR|2418|Adult.LSDIALER
PRCAT|8
FILEN|%Systemdrive%\ecommerce\dialer.ini
NEWPR|1151|Adultoweb Dialer
PRCAT|8
CLSIA|{067d7797-04fc-42b1-92db-81fc6cd318fd}
CLSIA|{23273a1c-c870-43c4-a3e3-67dc98630ac6}
CLSIA|{a45f39dc-3608-4237-8f0e-139f1bc49464}
CLSIA|{c771b05e-e725-4516-97a5-4ce5eb163cfb}
DIREC|%ProgramFiles%\fist\
AUTST|NsUpdate
RKSOF|GlobalCS
FILEN|%UserProfile%\Desktop\fist.LNK
FILEN|%UserProfile%\Start Menu\Programs\fist.LNK
NEWPR|1228|All-In-One Telcom
PRCAT|8
CLSID|{da9a0b0f-9b7b-11d3-b8a4-00c04f79641c}
CLSID|{da9a0b1d-9b7b-11d3-b8a4-00c04f79641c}
CLSID|{da9a0b1f-9b7b-11d3-b8a4-00c04f79641c}
CLASS|hadate file
CLASS|nsupdatelite.nsupdatelitectrl
RKSOF|hotactiondating
UINST|hotactiondating
NEWPR|2578|Andlotsmore.com dialer
PRCAT|8
NEWPR|820|babetv
PRCAT|8
CLSIA|{30ce93ae-4987-483c-9abe-f2bd5301ab70}
NEWPR|2588|BlondeSalope
PRCAT|8
NEWPR|779|BTV Dialer
PRCAT|8
DIREC|%ProgramFiles%\BTV\
DIREC|%ProgramFiles%\Common Files\midaddle\
DIREC|%programfiles%\diallerprogram\
AUTST|breg
NEWPR|2615|CAX Dialer
PRCAT|8
CLSIA|{2048b51e-8d74-4762-82ce-b48cf545eeea}
NEWPR|2579|CazzoCulo
PRCAT|8
NEWPR|2159|Central-24 Dialer
PRCAT|8
CLSID|{000000aa-abba-0704-0b53-2c8830e9faec}
CLSID|{0f4a7b40-a295-11cf-a3a9-00a0c9034920}
CLSID|{c60bc918-abba-0704-0b53-2c8830e9faec}
CLSIA|{dcf96da0-ed33-40ff-b83e-ab7011c2ba7e}
NEWPR|614|CrossKirk
PRCAT|8
CLSID|{0d639e64-5c31-4313-b62a-1b4d99e2f284}
CLSID|{3cd945a2-e413-4956-b9d8-a67fb6a7cb66}
CLSID|{9d6addbf-8227-4d36-ae46-116afbdafca0}
CLSID|{d24a1963-9951-4153-a340-6648759eb77d}
FILEN|crosskirk.cab
NEWPR|2593|Cuty girls
PRCAT|8
CLASS|XEng019.XEng019Ctl
NEWPR|2590|Cytainment
PRCAT|8
CLSIA|{00000000-abba-0704-0b53-2c8830e9faec}
CLASS| IELoaderCtl.IELoaderCtl
NEWPR|2251|Dataline Dialer
PRCAT|8
FILEN|dbn1742.exe
NEWPR|1968|Dialer-S
PRCAT|8
CLSID|{6986a6c2-9d58-11d6-91c2-00e02964e8e3}
CLASS|Pagomaster.IntPagomaster
FILEN|pagomaster.dll
NEWPR|1303|dialer-shop
PRCAT|8
CLSID|{6814a9ef-fbf1-46b2-a46e-56b401079c26}
CLSIA|{9d0a9d98-5221-430a-a02d-76f0827c82d1}
CLSIA|{d7b59209-0ed9-4986-bd4a-527be836c6b2}
NEWPR|2258|Dialer.ASDPlugin
PRCAT|8
AUTST|ASDPLUGIN
RKSOF|ASDPLUGIN
FILEN|%USERPROFILE%\Desktop\Launch DerBiz.com.lnk
FILEN|%USERPROFILE%\Desktop\Launch globalEaccess.lnk
FILEN|%userprofile%\Desktop\SurfYa.com.lnk
FILEN|%USERPROFILE%\Start Menu\Launch DerBiz.com.lnk
FILEN|%USERPROFILE%\Start Menu\Launch globalEaccess.lnk
FILEN|%userprofile%\Start Menu\SurfYa.com.lnk
FILEN|%USERPROFILE%\Start Menu\Uninstall Launch DerBiz.com.lnk
FILEN|%USERPROFILE%\Start Menu\Uninstall Launch globalEaccess.lnk
FILEN|%userprofile%\Start Menu\Uninstall SurfYa.com.lnk
FILEN|%Windir%\system32\dsldbaccess.exe
FILEN|%Windir%\system32\Geaccess.exe
NEWPR|2876|Dialer.Baj
PRCAT|8
NEWPR|2727|Dialer.BNI
PRCAT|8
NEWPR|1840|Dialer.Intexusdial
PRCAT|8
DIREC|%userprofile%\Start Menu\Programs\- tattooworld -
DIREC|%userprofile%\Start Menu\Programs\- tbuyit -
DIREC|%userprofile%\Start Menu\Programs\- Template-Tempel -
DIREC|%userprofile%\Start Menu\Programs\- testedich -
DIREC|%userprofile%\Start Menu\Programs\- Textfun.de - Witze und Sprueche -
DIREC|%userprofile%\Start Menu\Programs\- TheHentai.NET Hentai Erotik
DIREC|%userprofile%\Start Menu\Programs\- TheHentai.NET Hentai Erotik -
DIREC|%userprofile%\Start Menu\Programs\- Tierbabys -
DIREC|%userprofile%\Start Menu\Programs\- Tierheime -
DIREC|%userprofile%\Start Menu\Programs\- Toprezpte24 -
DIREC|%userprofile%\Start Menu\Programs\- Trilian-de -
DIREC|%userprofile%\Start Menu\Programs\- Tuerkei -
DIREC|%userprofile%\Start Menu\Programs\- TURKGAYS -
DIREC|%userprofile%\Start Menu\Programs\- UmsatzSteigern.de -
DIREC|%userprofile%\Start Menu\Programs\- Vornamen-Fundus -
DIREC|%userprofile%\Start Menu\Programs\- Wetter-Basis -
DIREC|%userprofile%\Start Menu\Programs\- witzealarm -
DIREC|%userprofile%\Start Menu\Programs\- Wohnung -
DIREC|%userprofile%\Start Menu\Programs\- XP-Antispy.de -
RKSOF|Intexus
RKSOF|IntexusDial
UINST|1md.de
FILEN|%userprofile%\Desktop\1md.de.lnk
FILEN|%userprofile%\Desktop\Anti-Report anti-report.lnk
FILEN|%userprofile%\Desktop\Counter.de counterde.lnk
FILEN|%userprofile%\Desktop\Fahrschule fahrschule.lnk
FILEN|%userprofile%\Desktop\GifProfi gifprofi.lnk
FILEN|%userprofile%\Desktop\gifsworld gifsworld.lnk
FILEN|%userprofile%\Desktop\Girlscam girlscam.lnk
FILEN|%userprofile%\Desktop\GrussProfi grussprofi.lnk
FILEN|%userprofile%\Desktop\HENTOON.DE hentai-de.lnk
FILEN|%userprofile%\Desktop\IQ Welt iqwelt.lnk
FILEN|%userprofile%\Desktop\iqtest iqtest.lnk
FILEN|%userprofile%\Desktop\lebenslauf.de lebenslauf-de.lnk
FILEN|%userprofile%\Desktop\Manga6.de manga6-de.lnk
FILEN|%userprofile%\Desktop\Megastars megastars.lnk
FILEN|%userprofile%\Desktop\Meine Seite meineseite.lnk
FILEN|%userprofile%\Desktop\Monster Vorlagen monstervorlagen.lnk
FILEN|%userprofile%\Desktop\MP3-Legal mp3-legal.lnk
FILEN|%userprofile%\Desktop\Neandertaler neandertaler.lnk
FILEN|%userprofile%\Desktop\neueinrichten.de neueinrichten-de.lnk
FILEN|%userprofile%\Desktop\Online Diaet onlinediaet.lnk
FILEN|%userprofile%\Desktop\Referate referate.lnk
FILEN|%userprofile%\Desktop\ReporteMafia.de reportemafia-de.lnk
FILEN|%userprofile%\Desktop\Reptilien.AG reptilien-ag.lnk
FILEN|%userprofile%\Desktop\Rezepte.AG rezepte-ag.lnk
FILEN|%userprofile%\Desktop\Rezeptsammlung.com rezeptsammlung-com.lnk
FILEN|%userprofile%\Desktop\Routenplaner Profi routenplanerprofi.lnk
FILEN|%userprofile%\Desktop\Sagen sagen.lnk
FILEN|%userprofile%\Desktop\schei1 schei1.lnk
FILEN|%userprofile%\Desktop\Schoener werden schoenerwerden.lnk
FILEN|%userprofile%\Desktop\schulstadt schulstadt.lnk
FILEN|%userprofile%\Desktop\sexworld sexworld.lnk
FILEN|%userprofile%\Desktop\Smilie-Fabrik smilie-fabrik.lnk
FILEN|%userprofile%\Desktop\Spasspilot.de spasspilot-de.lnk
FILEN|%userprofile%\Desktop\Spieleindex spieleindex.lnk
FILEN|%userprofile%\Desktop\Sprueche.de sprueche-de.lnk
FILEN|%userprofile%\Desktop\Supergames supergames.lnk
FILEN|%userprofile%\Desktop\Taroskop.de taroskop-de.lnk
FILEN|%userprofile%\Desktop\Tattoo Mania tattoomania.lnk
FILEN|%userprofile%\Desktop\tattoopalace tattoopalace.lnk
FILEN|%userprofile%\Desktop\tbuyit tbuyit.lnk
FILEN|%userprofile%\Desktop\Template-Tempel template-tempel.lnk
FILEN|%userprofile%\Desktop\testedich testedich.lnk
FILEN|%userprofile%\Desktop\Textfun.de - Witze und Sprueche textfun-de.lnk
FILEN|%userprofile%\Desktop\TheHentai.NET Hentai Erotik thehentai-net.lnk
FILEN|%userprofile%\Desktop\Tierbabys tierbabys.lnk
FILEN|%userprofile%\Desktop\Toprezpte24 toprezpte24.lnk
FILEN|%userprofile%\Desktop\Trilian-de trilian-de.lnk
FILEN|%userprofile%\Desktop\Vornamen-Fundus vornamen-fundus.lnk
FILEN|%userprofile%\Desktop\XP-Antispy.de xp-antispy-de.lnk
FILEN|%userprofile%\Recent\Intexusdial.cc.lnk
FILEN|%userprofile%\Start Menu\Programs\- GifProfi -\GifProfi gifprofi.lnk
FILEN|%userprofile%\Start Menu\Programs\- gifsworld -\gifsworld gifsworld.lnk
FILEN|%userprofile%\Start Menu\Programs\- Girlscam -\Girlscam girlscam.lnk
FILEN|%userprofile%\Start Menu\Programs\- Megastars -\Megastars megastars.lnk
FILEN|%userprofile%\Start Menu\Programs\- Meine Seite -\Meine Seite meineseite.lnk
FILEN|%userprofile%\Start Menu\Programs\- Monster Vorlagen -\Monster Vorlagen monstervorlagen.lnk
FILEN|%userprofile%\Start Menu\Programs\- Neandertaler -\Neandertaler neandertaler.lnk
FILEN|%userprofile%\Start Menu\Programs\- neueinrichten.de -\neueinrichten.de neueinrichten-de.lnk
FILEN|%userprofile%\Start Menu\Programs\- Online Diaet -\Online Diaet onlinediaet.lnk
FILEN|%userprofile%\Start Menu\Programs\- Referate -\Referate referate.lnk
FILEN|%userprofile%\Start Menu\Programs\- ReporteMafia.de -\ReporteMafia.de reportemafia-de.lnk
FILEN|%userprofile%\Start Menu\Programs\- Reptilien.AG -\Reptilien.AG reptilien-ag.lnk
FILEN|%userprofile%\Start Menu\Programs\- Rezepte.AG -\Rezepte.AG rezepte-ag.lnk
FILEN|%userprofile%\Start Menu\Programs\- Rezeptsammlung.com -\Rezeptsammlung.com rezeptsammlung-com.lnk
FILEN|%userprofile%\Start Menu\Programs\- sexworld -\sexworld sexworld.ln
FILEN|%userprofile%\Start Menu\Programs\- sharing.ag -\sharing.ag share-dialer.lnk
FILEN|%userprofile%\Start Menu\Programs\- Smiley Castle -\Smiley Castle smileycastle.lnk
FILEN|%userprofile%\Start Menu\Programs\- TheHentai.NET Hentai Erotik -\TheHentai.NET Hentai Erotik thehentai-net.lnk
FILEN|2da45.exe
FILEN|alternativ-heilung.com ahm-10056.lnk
FILEN|beauty[schoenerwerden,1].exe
FILEN|bpmk.dat
FILEN|cocktails[ccp-10097,de].exe
FILEN|gifsworld[gwd-10927,de].exe
FILEN|hausaufgaben[hun-10002,de].exe
FILEN|hausaufgaben[hun-10222,de].exe
FILEN|horoskop_erstellen[aie-10070,de].exe
FILEN|lehrstellen[lhs-10004,de].exe
FILEN|liebesbriefe[lbi-10023,de,start].exe
FILEN|pflanzen[pla-10006,de].exe
FILEN|routenplanerag.exe
FILEN|sagen.exe
FILEN|satanismus.exe
FILEN|satfrequenzen.exe
FILEN|scheisse[schei1,1].exe
FILEN|schulstadt-1.exe
FILEN|schulstadt-2.exe
FILEN|schulstadt-3.exe
FILEN|schulstadt-4.exe
FILEN|schulstadt-5.exe
FILEN|schulstadt-6.exe
FILEN|schulstadt-7.exe
FILEN|schulstadt.exe
FILEN|schwanger.exe
FILEN|setup(1-1md-0-0-,us)-1.exe
FILEN|sexworld[sexworld,1].exe
FILEN|sharing-ag-1.exe
FILEN|sharing-ag.exe
FILEN|slowenien.de.exe
FILEN|smiley[smileycastle,1].exe
FILEN|smiley[syc-10008,1].exe
FILEN|smilie-fabrik.exe
FILEN|sms-stadt-1.exe
FILEN|sms-stadt-2.exe
FILEN|sms-stadt-3.exe
FILEN|sms-stadt.exe
FILEN|sms-tool.exe
FILEN|songtexte[sgx-10001,1].exe
FILEN|songtextzone-1.exe
FILEN|songtextzone-2.exe
FILEN|songtextzone-4.exe
FILEN|spass4u[s4e-10020,1].exe
FILEN|spasspilot-1.exe
FILEN|spicktricks[ree-10323,de].exe
FILEN|spieledownload[ssg-10001,1,a63e].exe
FILEN|spieleindex[spieleindex,1].exe
FILEN|spiele_runterladen[geg-10066,1].exe
FILEN|sprueche.exe
FILEN|stammbaum.de.exe
FILEN|starfuck.exe
FILEN|stars-nackt.exe
FILEN|sternzeichen[szn-10011,de].exe
FILEN|straflos[anti-report,1].exe
FILEN|suchmaschinen-1.exe
FILEN|supergames[supergames,1].exe
FILEN|taroskop.exe
FILEN|tattoo-1.exe
FILEN|tattoo-2.exe
FILEN|tattoopalace-11.exe
FILEN|tattoos[tod-10109,de].exe
FILEN|tattoos[tod-10133,1].exe
FILEN|tattoovorlagen-de[toe-10362,1]-2.exe
FILEN|tattoo[tattoomania,1].exe
FILEN|tattoo[toe-10082,1].exe
FILEN|template-tempel.exe
FILEN|tests[iqwelt,1].exe
FILEN|test[teh-10116,de,start4].exe
FILEN|tierbabys[tierbabys,1].exe
FILEN|toprezept.exe
FILEN|trilian[trilian-de,1].exe
FILEN|tuerkei.exe
FILEN|turkgays[tks-10001,1].exe
FILEN|umsatzsteigern[uee-10001,1].exe
FILEN|valueradio-1.exe
FILEN|vornamen.exe
FILEN|vornamen[vnf-10049,1].exe
FILEN|vornamen[vnf-10103,1].exe
FILEN|wetter-basis-1.exe
FILEN|wetter-basis.exe
FILEN|witzealarm.exe
FILEN|witze[counterde,1].exe
FILEN|wohnung.exe
NEWPR|2281|Dialer.ks
PRCAT|8
CLSID|{3eb94323-0856-4479-aa22-d81bbfeea91e}
CLSID|{6bc36767-3fcc-4948-8a13-703f887a3e87}
CLSIA|{e53458d2-5a83-4bd1-8de2-eeebe73bab49}
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\C:/WINDOWS/system32/ccaccess.dll
CLASS|Ccaccess.CheckControl
NEWPR|2714|Dialer.Maxd
PRCAT|8
FILEN|maxd641.exe
NEWPR|2119|Dialer.Mostrar
PRCAT|8
CLSID|{095c0db4-fea6-440e-8dfc-00fc53ac827d}
CLSID|{4fc63700-2093-4ad2-8d37-3b3d86d9c940}
CLSID|{5bf0ce3e-61d2-4a7b-baa3-0c4667a9563d}
CLSIA|{88c51e90-8e9c-4c96-8a45-574d88b63faf}
CLSIA|{ffff0003-0001-101a-a3c9-08002b23e0cc}
CLSIA|{ffff0003-0001-101a-a3c9-08002b23e0cd}
REGKE|HKEY_CURRENT_USER\PTPSA32.PTPSAWeb
AUTST|Dialer
CLASS|PTPSA32.PTPSAWeb
FILEN|%windir%\Downloaded Program Files\msa64chk.inf
NEWPR|3532|Dialer.Qi
PRCAT|8
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Emitt
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform , ADVPLUGIN|K115|165|S-866237264|dialno
AUTST|auoie
IEZON|nodialup.name
IEZON|whatsnew.name
FILEN|syslcznp.exe
NEWPR|2609|Dialer.Sfonditalia
PRCAT|8
IEZON|realarea.biz
NEWPR|2877|Dialer.XD
PRCAT|8
NEWPR|2557|DialerActiveX
PRCAT|8
CLSID|{660b7669-1a16-4864-ac91-8ecbbe7de93f}
CLSID|{8e224ed3-c09f-4ff9-9ace-883d99498f26}
CLSID|{aee9cc65-40f3-4f61-b919-a728bc526d58}
CLSID|{b27bf58e-619c-43f6-8f2a-e4c6428b5245}
CLASS|DIALERACTIVEX.DialeractivexCtrl
NEWPR|406|DialerFactory
PRCAT|8
NEWPR|473|DialerOffline
PRCAT|8
CLSID|{1773b696-b019-4fc1-9eed-b1c7f925f56a}
CLSID|{20270406-63ad-4c7e-ae8d-bb632e508ace}
CLSID|{271d7d74-8e6d-4e6c-86f5-66c064cfb74d}
CLSID|{89161220-a3d9-464f-848c-4ebe0546697d}
CLSID|{a8882720-e26c-4073-8b8a-981d32882af7}
CLSID|{b0acf771-f0f7-461f-bef3-5b1a3ba42f51}
CLSID|{cabd7099-6b04-471d-8371-9fde9c2e6bea}
CLSIA|{ceb29da4-7afa-4f24-b3cd-17351d590df0}
FILEN|dialeroffline.dll
NEWPR|821|DialXS
PRCAT|8
CLSIA|{9b4aa442-9ebf-11d5-8c11-0050da4957f5}
CLASS|DialXS.DialXSCtl
NEWPR|2861|E-nrgyPlus Dialer
PRCAT|8
DIREC|%allusersprofile%\Start Menu\Programs\E-nrgyPlus\
DIREC|%programfiles%\E-nrgyPlus\
AUTST|E-nrgyPlus
NEWPR|2514|Edipole
PRCAT|8
CLASS|WebInstall.WWWInstall
NEWPR|2829|Eocha
PRCAT|8
CLSIA|{2f6c63df-48ad-44c3-a761-7fb53ecf064a}
CLSIA|{3a4dcd02-a451-4799-9e1c-ac0d4f769a97}
CLSIA|{3f5e67e1-81e6-4487-bf6f-07941a080bab}
CLSIA|{3fa96320-481c-4af4-819a-968a6426928e}
CLSIA|{4360e841-fe3e-427f-98dc-7abc8ace6665}
CLSIA|{4d4c0269-8303-4448-80dc-a3de34bc5374}
CLSIA|{5c626a4f-28a7-4a29-9ec8-6be20fc70424}
CLSIA|{72e0f892-b9f1-451d-95a3-2e6c1f45c0dd}
CLSIA|{73b9a791-ba9e-418a-b5a4-948b63be04f7}
CLSID|{8431328a-1050-42a8-a615-809f40d3037d}
CLSID|{8dab5c8c-c784-4651-84f7-b6c9f4eec53d}
CLSIA|{96966b7c-ca72-4928-895b-1c2f0e5302a9}
CLSIA|{9caee012-5dff-11db-8373-b622a1ef5492}
CLSIA|{9f54bf10-c88e-43fd-aa9e-16bf45747c72}
CLSIA|{9f5bb9e1-31ae-4a13-8734-15ced0f60a3d}
CLSIA|{ca654d30-99f2-4dd1-b58c-767e2bb862ff}
CLSIA|{ea5b2f8a-2094-47a1-adc5-373e93eaf936}
CLSIA|{ea8804ce-a2f0-4773-89b8-1e5168a1d8d7}
CLSIA|{eb5cdbc6-dba4-48bc-b888-5e2cff9df3cd}
CLSIA|{f40f43f6-890c-479d-a996-306123662084}
DIREC|%ProgramFiles%\SmilEmail\
AUTST|ciakaisen.exe
AUTST|lateshow.exe
AUTST|MicrosoftFirewall
AUTST|MSGlobal
AUTST|MSMalwareKit
AUTST|SmilEmail
AUTST|StopPhish
AUTST|wke.exe
CLASS|ActiveXCOM.myActiveXCOM
CLASS|XBTB08814.IEToolbar
RKSOF|ADWhere Component
RKSOF|Coprocefalo
RKSOF|XBTB08814
UINST|XBTB08814.XBTB08814Toolbar
FILEN|%USERPROFILE%\My Documents\My Music\PrintHood\Canon BJC su Giorgia.lnk
FILEN|%USERPROFILE%\My Documents\My Music\The Clash.lnk
FILEN|%USERPROFILE%\Start Menu\messaggio3.exe
FILEN|%USERPROFILE%\Start Menu\Vocabolario.lnk
IEZON|cds.zangocash.com
IEZON|ciritorno.biz
IEZON|content.licenseacquisition.org
IEZON|cywanstorage.biz
IEZON|defaultbar.com
IEZON|licenseacquisition.org
IEZON|melagodo.biz
IEZON|pergentina.biz
IEZON|playmore.biz
IEZON|preferiti-windows.com
IEZON|static.zangocash.com
IEZON|terzodesiderio.biz
IEZON|www.acquadirose.com
IEZON|www.ciritorno.biz
IEZON|www.defaultbar.com
IEZON|www.forteforte.com
IEZON|www.melagodo.biz
IEZON|www.nanobyte.biz
IEZON|www.pergentina.biz
IEZON|www.phishingfix.biz
IEZON|www.playmore.biz
IEZON|www.popup-freesex-adv.biz
IEZON|www.preferiti-windows.com
IEZON|www.ricercadoppia.com
IEZON|www.scalalap.com
IEZON|www.sextriere.com
IEZON|www.smilemail.biz
IEZON|www.super-videochat-community.biz
IEZON|www.terzodesiderio.biz
IEZON|www.tuttaqualita.com
IEZON|www.umts-gprs-mondo-telefonino-cellulare.biz
IEZON|www.virgilio.in
IEZON|www.what-you-want.biz
NEWPR|2671|Eroskop Dialer
PRCAT|8
AUTST|AntyVirKS
NEWPR|784|EroticAccess
PRCAT|8
CLSIA|{1230cb21-c88d-11cf-b347-000000000000}
CLSIA|{73f0fd85-bd47-4a95-86d1-de38860462c1}
NEWPR|2402|FairTale
PRCAT|8
CLSID|{adb5c6a6-4595-4038-859b-d213969892a3}
CLSID|{e2bba7ac-2347-4761-af7a-0dca61355d53}
CLSID|{e5502c44-565e-4897-819f-c6abae1f89fb}
DIREC|%systemdrive%\fairtale\
CLASS|.ft0
CLASS|Fairtale
CLASS|fairtale.Class1
NEWPR|1798|FairyTale
PRCAT|8
CLSIA|{940ec490-8c20-4360-a725-1f44984933df}
CLSIA|{99e79790-2b09-11d6-8c73-0800460222f0}
NEWPR|2582|FanAlizee
PRCAT|8
NEWPR|2755|FanNolwenn
PRCAT|8
FILEN|%USERPROFILE%\Desktop\FanNolwenn.lnk
FILEN|%USERPROFILE%\Start Menu\FanNolwenn.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\HOT Dialer\FanNolwenn.lnk
FILEN|%USERPROFILE%\Start Menu\Programs\HOT Dialer\Uninstall FanNolwenn.lnk
NEWPR|2591|FanSalma
PRCAT|8
NEWPR|788|FreeLoad
PRCAT|8
NEWPR|2528|Fundial
PRCAT|8
CLSID|{1f20cf42-b381-4181-8c2a-a389b1022e6e}
CLSID|{703e919d-28c9-4491-8d01-8964e47bbbba}
DIREC|%SystemDrive%\dialerfun\
CLASS|Dialer.Class1
NEWPR|2475|Gamesplayground
PRCAT|8
CLSIA|{fde6b956-b80a-4578-9a10-4c24609412f1}
NEWPR|679|GlobalDialer
PRCAT|8
CLSIA|{05d087e7-51bd-3f5b-7bb5-0c6a120fc11a}
CLSIA|{11111111-1111-1111-1111-511111193457}
CLSIA|{11111111-1111-1111-1111-511111193458}
CLSIA|{11111111-1111-1111-1111-611111193457}
CLSIA|{11111111-1111-1111-1111-611111193458}
CLSIA|{11111111-1111-1111-1114-511155593469}
CLSID|{12c94089-40ef-4885-860a-6cdd3e138a20}
CLSIA|{22222222-2222-2222-4444-566661888858}
CLSIA|{23232323-2323-2323-2323-232323231122}
CLSIA|{23232323-2323-2323-2323-232323291122}
CLSIA|{2dc2b96e-1748-11d5-94e4-006008a4ed7f}
CLSIA|{38545c2a-03cd-42c3-bc62-c537a6d5a8f6}
CLSIA|{413a0886-cbc2-4cbe-bbc7-3b423eb15383}
CLSID|{5d945e9a-dc10-4670-83eb-99daa616628a}
CLSIA|{5f944a91-2888-1cef-ffff-7b632dba7c98}
LSIA|{6a5081c6-d0f7-5f22-467f-40610638bfca}
CLSIA|{753c42af-4e2e-5334-f69c-45732649b667}
CLSIA|{7cd66bd1-e395-0425-146c-46cd022dc162}
CLSIA|{861fda2a-2b57-4bda-8b8b-305c9d5d8604}
CLSIA|{97b79133-88f0-45f0-8d57-0f2ef27d9c66}
CLSIA|{b3aa2f6b-6baf-11d3-ba05-00c0f0322972}
CLSIA|{b94b4225-e02e-4d3f-badb-026f1e2f3ad7}
CLSIA|{d22ac3ef-b7d8-11d5-a281-005056bf0101}
CLSIA|{d52d92f2-3650-439c-aa18-03ee4f6859de}
CLSIA|{deda29ca-3653-456e-b4c9-63a5d85d35d6}
CLSIA|{faff0003-0a01-121a-a1c9-08032b23e0cc}
CLSIA|{ff3f0f03-0f01-131a-a3f9-08f02b23e0cc}
CLSIA|{fffb1d8b-88d6-4c91-bb62-378625e8c73e}
CLSIA|{ffff0018-0001-101a-a3c9-08002b2f49fb}
DIREC|%ProgramFiles%\GlobalDialer\
AUTST|sws.exe
AUTST|w32sup
CLASS|Gxbplug.plug
CLASS|Loader.LoaderObj
CLASS|OLibrary.IEPlugIn
CLASS|Suchspur.SuchspurObj
RKSOF|Gxb
UINST|GlobalDialer
FILEN|gd-ff_be.exe
FILEN|gd-ff_us.exe
FILEN|gdnca167.exe
FILEN|globaldialer.cab
FILEN|olibrary.dll
NEWPR|2512|GoIn Direct Dialer
PRCAT|8
NEWPR|645|Hacker Spider
PRCAT|8
DIREC|%windir%\coder
UINST|Exclusiver Bereich
FILEN|%userprofile%\Desktop\Exclusiver Bereich.lnk
FILEN|%userprofile%\Start Menu\Programs\Exclusiver Bereich.lnk
FILEN|hacker spider.exe
NEWPR|709|Haldex
PRCAT|8
DIREC|%programfiles%\HaldexLtd\
NEWPR|407|HighSpeed Connector
PRCAT|8
FILEN|123-sexkino.exe
FILEN|aktgirls.exe
FILEN|aktshow.exe
FILEN|amateur-hardcore-sex.exe
FILEN|analorgasmus.exe
FILEN|analxxx.exe
FILEN|babesex.exe
FILEN|begleitung-online.exe
FILEN|berlin-erotik.exe
FILEN|betnaker.exe
FILEN|bigbusen.exe
FILEN|bumsmich.exe
FILEN|bundesligagirls.exe
FILEN|busencam.exe
FILEN|busenline.exe
FILEN|busenshow.exe
FILEN|busentreff.exe
FILEN|busenweb.exe
FILEN|camcontrol.exe
FILEN|casarossa.exe
FILEN|city-girls.exe
FILEN|clickfick.exe
FILEN|computersex.exe
FILEN|cyber-angels.exe
FILEN|cybererotiva.exe
FILEN|debabes.exe
FILEN|degirls.exe
FILEN|deutsch.exe
FILEN|devotelust.exe
FILEN|disnex.exe
FILEN|donnavargas.exe
FILEN|dream-sex.exe
FILEN|e-kontakte.exe
FILEN|ecsfun.exe
FILEN|ero-world.exe
FILEN|eroclick.exe
FILEN|eroklick.exe
FILEN|erophone.exe
FILEN|eroplanet.exe
FILEN|erotic-news.exe
FILEN|eroticenter.exe
FILEN|eroticliveshow.exe
FILEN|erotik-news.exe
FILEN|euromodels2.exe
FILEN|fickclick.exe
FILEN|fickenonline.exe
FILEN|fickklick.exe
FILEN|fickline.exe
FILEN|fickschule.exe
FILEN|ficksie.exe
FILEN|fussballgirls.exe
FILEN|germany.exe
FILEN|gina-wild-sex.exe
FILEN|girls.exe
FILEN|girlsbesuch.exe
FILEN|girlshotel.exe
FILEN|girlstalk.exe
FILEN|glas-haus.exe
FILEN|hardcore-live-sex.exe
FILEN|hooters.exe
FILEN|hotbunny.exe
FILEN|hotelbesuch.exe
FILEN|hotelgirls.exe
FILEN|hotpower.exe
FILEN|hotvot.exe
FILEN|hotwied.exe
FILEN|klickfick.exe
FILEN|kontaktechat.exe
FILEN|lesbenhaus.exe
FILEN|life-girl.exe
FILEN|lifegirl.exe
FILEN|live-studio.exe
FILEN|livechatcam.exe
FILEN|livephone.exe
FILEN|livesex.exe
FILEN|livesexkanal.exe
FILEN|liveshow.exe
FILEN|lovephone.exe
FILEN|lucky-punch.exe
FILEN|macronedia.exe
FILEN|maxxcafe.exe
FILEN|meetboys.exe
FILEN|meinecam.exe
FILEN|moesenhaus.exe
FILEN|mytits.exe
FILEN|nacktshow.exe
FILEN|nudeliveshow.exe
FILEN|online-begleitung.exe
FILEN|online-escort.exe
FILEN|orgasmusbilder.exe
FILEN|orgasmusline.exe
FILEN|orgasmuslive.exe
FILEN|orgasmusparty.exe
FILEN|orgasmusvideo.exe
FILEN|osnastrip.exe
FILEN|pagesex.exe
FILEN|pam.exe
FILEN|peep-show-girls.exe
FILEN|persiankitti.exe
FILEN|persianklitty.exe
FILEN|phonegirl.exe
FILEN|phythom.exe
FILEN|playboobs.exe
FILEN|playgal.exe
FILEN|playmoesen.exe
FILEN|playmuschi.exe
FILEN|porncam.exe
FILEN|porno-porno-sex-sex.exe
FILEN|pornodelux.exe
FILEN|pornomoesen.exe
FILEN|privatbesuch.exe
FILEN|pussygeil.exe
FILEN|pussyhaus.exe
FILEN|redlightgirls.exe
FILEN|rotlichtchat.exe
FILEN|rotlichtgirls.exe
FILEN|rotlichtline.exe
FILEN|rotlichtshow.exe
FILEN|schulsex.exe
FILEN|sex-erotik-show.exe
FILEN|sex-live-chat.exe
FILEN|sex-porno-show.exe
FILEN|sex-rooms.exe
FILEN|sex-sex-porno-porno.exe
FILEN|sex-sex-sex-pussy.exe
FILEN|sex-tabulos.exe
FILEN|sexcall.exe
FILEN|sexdominanz.exe
FILEN|sexevents.exe
FILEN|sexfetish.exe
FILEN|sexillusion.exe
FILEN|sexkarussell.exe
FILEN|sexkeller.exe
FILEN|sexme.exe
FILEN|sexmich.exe
FILEN|sexpicturegallery.exe
FILEN|sexroulette.exe
FILEN|sexschule.exe
FILEN|sextacy.exe
FILEN|sexycamera.exe
FILEN|smutlamd.exe
FILEN|soos.exe
FILEN|strapsshow.exe
FILEN|strichgirls.exe
FILEN|strip-eonline.exe
FILEN|strip-girls.exe
FILEN|stripcan.exe
FILEN|striplime.exe
FILEN|stripline.exe
FILEN|strippenonline.exe
FILEN|stripschule.exe
FILEN|studiosex.exe
FILEN|suendenspiele.exe
FILEN|teenmail.exe
FILEN|telestrip.exe
FILEN|the-sweets.exe
FILEN|tittengeil.exe
FILEN|tittenline.exe
FILEN|tittenseite.exe
FILEN|tittenspiele.exe
FILEN|tittenweb.exe
FILEN|tittenwelt.exe
FILEN|travelsex24.exe
FILEN|venusgirls.exe
FILEN|venusphone.exe
FILEN|victoriasecreet.exe
FILEN|videochatcam.exe
FILEN|viona.exe
FILEN|vollbusicam.exe
FILEN|wichsen.exe
FILEN|wild-sex.exe
FILEN|xxxphone.exe
NEWPR|1238|Holystic
PRCAT|8
CLSIA|{037b3d58-d14a-4c41-bdfd-bd779b0b97ba}
CLSIA|{03c543a1-c090-418f-a1d0-fb96380d601d}
CLSIA|{0733b8f9-8b52-4693-a9fa-829e12d27f78}
CLSIA|{0873478e-e67a-4876-b0a9-9a36d3ab3602}
CLSIA|{0cb2bd5a-7a80-4ba9-b49a-02dc51144bdf}
REGKE|HKEY_CLASSES_ROOT\HOL3_VXIEWER.FULL.1
REGKE|HKEY_CLASSES_ROOT\HOL_PRELOAD.FULL.1
NEWPR|408|HotActionDating
PRCAT|8
FILEN|hotactiondating-uninstall.exe
FILEN|hotactiondating.exe
FILEN|nsi145.exe
NEWPR|2583|Hot_Pleasure
PRCAT|8
REGKE|HKEY_CURRENT_USER\Software\SiteIcons\Dialers
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pmxy
REGKE|HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-pmxy
AUTST|LiveSexCams
CLASS|pmxy File
UINST|LiveSexCams
FILEN|%USERPROFILE%\Desktop\LiveSexCams.lnk
NEWPR|771|Ibero Dialer
PRCAT|8
CLSIA|{19e0f68f-c0ef-4241-b876-a3d646995895}
CLSIA|{1d7532ce-995b-40f2-8c17-2e01af16ffac}
CLSIA|{2c0f2aea-3a9b-46db-a7be-80ff329e415d}
CLSIA|{571c345e-7356-444b-a4e2-1b6442f96ebc}
CLSIA|{b15108aa-d8d0-480d-b535-07e18d6549a8}
CLSIA|{fb8d70e2-554a-4c75-90be-66c302367e0d}
FILEN|ppremiuminternacional.dll
NEWPR|432|IBS
PRCAT|8
FILEN|gratis-sex-crack.exe
FILEN|traumdate.exe
NEWPR|456|IEAccess
PRCAT|8
CLSIA|{0594af7e-573b-40df-8165-e47ab2eaefe8}
CLSIA|{11f1d260-129e-4eb7-b37e-57e3d97a3df1}
CLSIA|{1a9ec776-942a-4a51-8cd6-0dd9c25ed05b}
CLSIA|{1d2dca0d-b30f-40ad-9690-087105f214ec}
CLSIA|{1eb17d1c-141d-4d9d-91cb-24d99215851d}
CLSIA|{2abe804b-4d3a-41bf-a172-304627874b45}
CLSIA|{2aeeac34-fd74-4142-b891-4b05c0c03c87}
CLSID|{2f668a6d-2ec7-4e3a-a485-819e210738d6}
CLSID|{4209b4c1-1295-4908-9312-a53c036eb3cd}
CLSIA|{469c7080-8ec8-43a6-ad97-45848113743c}
CLSIA|{486e48b5-abf2-42bb-a327-2679df3fb822}
CLSIA|{50ad557e-3426-41fd-afdd-2af39bb1c387}
CLSID|{62bfaec2-82a5-4117-a98b-fea89413d924}
CLSIA|{6aa93df6-6757-4338-9087-f7601de18402}
CLSIA|{71cbdcd9-0830-4470-a890-35d364da352c}
CLSID|{7699aef9-f83a-44fa-b374-aa02cedf247d}
CLSIA|{77ef6dbf-3929-4081-af2e-178d387e211c}
CLSIA|{79733e69-6e1c-4682-bdf5-710d217a4125}
CLSID|{81c2f7f3-f930-455e-9aa5-0876d387c787}
CLSID|{83f0d6aa-cd15-46b5-aa4e-bdb506b4ae53}
CLSIA|{8b936702-c234-40d0-b69c-a2f669a33978}
CLSID|{901166a5-f137-4b27-bc4c-ca611debdced}
CLSIA|{946b0485-8f8c-4c35-a6e7-d2115e3b0b4f}
CLSIA|{94f5dcb7-816c-4b94-a2c1-856c6e323c5b}
CLSIA|{99ff4323-e68c-46dc-8f48-1f79a7005336}
CLSIA|{9c020689-fa7d-4d8d-be7e-dc263791cb29}
CLSIA|{9ef4e3e4-2f1e-472e-9ff2-2670ea5c42d9}
CLSIA|{a02780c3-7f77-4e28-855b-28890f3cf37a}
CLSIA|{afcf364f-f730-4b1e-b2d5-80f9172fbc44}
CLSIA|{b843da96-2b2d-447e-90ab-b92929aa11af}
CLSIA|{bd3653e4-884b-43c4-970b-670802501b7f}
CLSIA|{be5a7132-329f-4319-b781-2a83bfe51534}
CLSIA|{c20eb175-0dd0-4979-a994-1f0dba69f627}
CLSIA|{c9269872-e3d6-4811-8e5e-835ca8cbd0b3}
CLSIA|{caaf9105-a683-4ed1-89cc-18f6d194dd84}
CLSIA|{cdd8bade-b4c8-4e97-84b4-1dc9abad3ef3}
CLSIA|{cefb7b49-9652-464f-8afd-a577c05