Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > HijackThis Log Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

Resolved HJT Threads Resolved spyware and popup issues.

 
 
Thread Tools
Old 09-02-2005, 04:28 PM   #1 (permalink)
Registered User
 
Join Date: Sep 2005
Posts: 6
OS: WinXP


hijack file for yieldmanager problem

Hi, I'm very new to this so please bare with me. I have some kind of malware that's causing constant popups mostly from ad.yieldmanager though there are others. I've run Adware, SpyS&D, Ewido and others. Looking for any possible help with this. Thanks!

Logfile of HijackThis v1.99.1
Scan saved at 6:14:50 PM, on 9/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\WINDOWS\ZGVmYXVsdAAA\command.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\medgs1.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MESSEN~1\msmsgs.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
C:\Program Files\Common Files\efax\Dllcmd32.exe
C:\Program Files\Common Files\efax\HotTray.exe
C:\Program Files\MTV Networks\VOpt\MTVOptTray.exe
C:\Program Files\MTV Networks\VOpt\MTVOptQueue.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [%%DELETE_VALUE%%] CreateCD50
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SearchUpgrader] C:\Program Files\Common files\SearchUpgrader\SearchUpgrader.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [tsvcin] C:\WINDOWS\system32\n20050308.EXE
O4 - HKLM\..\Run: [p4mX37l] snmtview.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [MedGS] C:\WINDOWS\system32\medgs1.exe
O4 - HKLM\..\Run: [opr] C:\WINDOWS\system32\opr.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\PROGRA~1\MESSEN~1\msmsgs.exe" /background
O4 - HKCU\..\Run: [Y357RXJ7g] smbpol.exe
O4 - HKCU\..\Run: [qkmo] C:\PROGRA~1\COMMON~1\qkmo\qkmom.exe
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000079.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-110-12-0000079.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Global Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Global Startup: Live Menu.lnk = C:\Program Files\Common Files\efax\Dllcmd32.exe
O4 - Global Startup: eFax.com Tray Menu.lnk = C:\Program Files\Common Files\efax\HotTray.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: MTV Networks Video Optimizer.lnk = C:\Program Files\MTV Networks\VOpt\MTVOptTray.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://education.dellnet.com/ (file missing) (HKCU)
O16 - DPF: Yahoo! PagerLite - http://jpager.yahoo.com/m6/msgr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/k...an_unicode.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a224.g.akamai.net/7/224/52/20...eInstaller.exe
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.25.152/code/PWActiveXImgCtl.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {CE74A05D-ED12-473A-97F8-85FB0E2F479F} (dlControl.UserControl1) - https://stores.musictoday.com/store/...ugsActiveX.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite...ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {FCEAE646-DCF9-4D59-B994-6BD30A315139} - http://www.mtv.com/overdrive/bin/setup.exe
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/...ampx_en_dl.cab
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\ZGVmYXVsdAAA\command.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
iambaytor is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 09-03-2005, 06:07 AM   #2 (permalink)
Moderator, Microsoft Support
 
POADB's Avatar
 
Join Date: Jul 2004
Location: United Kingdom
Posts: 6,211
OS: XP SP2


Hi and Welcome to TSF!

Please subscribe to this thread to be notified of fixes as soon as they are posted by our Team. To do this, please click the "Thread Tools" button located in the original thread line and selecting "Subscribe to this Thread".

Save the next instructions in notepad, because you also have to work in safe mode without networking support, so this page wouldn't be available then. You should not have any browsers on.

If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are carrying out the procedures below.

It is also important you don't miss a step and perform everything in the right order!!. .


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Please download these additional files/programs. Do not run them unless instructed to do so.
Unless otherwise stated, they should be stored in same directory as the HiJackThis program.

Please download Trend Micro™ Anti-Spyware for the Web Utility (by clicking the "Scan and Clean your PC" button).
  • Save it to your desktop.
  • Double-click the new icon on your desktop (tmas-web-scan.exe)
  • It will say "Loading TrendMicro definitions".
  • Once the definitions are loaded, the program will appear to close then re-open.
  • Click "Start Scan"
  • After it's done scanning, click "Scan Results"
  • Make sure all items found have a check next to them, then click "Clean Threats Now".
  • Click Exit.
Reboot your computer. In place of the TrendMicro icon will be a text file called "Antispyware.log", please double-click that log and copy the entire contents and paste them in your next post.

Unplug your computer from the Internet when you have finished downloading


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Click Start>Run - type services.msc.
Locate the Command Service (cmdService) service and double-click on it to open the Properties dialog.
Click the Stop button.
In the Startup type dropdown select Disabled.
Click the Apply button and then the Ok button.

Then start HiJackThis & go to Config>Misc.Tools...> Delete an NT service...
In the popup box that appears, type in cmdService & click the OK button.


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

REBOOT TO SAFE MODE
  1. Restart the computer. The computer begins processing a set of instructions known as BIOS.
  2. As soon as the BIOS has finished loading, begin tapping the F8 key on your keyboard.
  3. Continue to do so until the 'Windows Advanced Options' menu appears.
  4. Using the arrow keys on the keyboard, scroll to and select the menu item - Safe Mode.


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Enable the viewing of Hidden files
  1. From Windows Explorer, go to Tools>Folder Options>View tab.
  2. Enable the option for `Show hidden files and folder´
  3. Disable the option for `Hide file extensions for known types´
  4. Disable the option for `Hide protected operating system files´
  5. Click Yes to confirm & then click OK

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Uninstall the following programs, if present, using Control Panel > Add/Remove Programs :
  • Internet Explorer Web Content Catcher

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Run a scan with HiJackThis & select(tick) the following & click [Fix checked] :

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: Internet Explorer Web Content Catcher - {FFF4E223-7019-4ce7-BE03-D7D3C8CCE884} - C:\Program Files\DNS\Catcher.dll O4 - HKLM\..\Run: [tsvcin] C:\WINDOWS\system32\n20050308.EXE
O4 - HKLM\..\Run: [p4mX37l] snmtview.exe
O4 - HKLM\..\Run: [MedGS] C:\WINDOWS\system32\medgs1.exe
O4 - HKLM\..\Run: [opr] C:\WINDOWS\system32\opr.exe
O4 - HKCU\..\Run: [Y357RXJ7g] smbpol.exe
O4 - HKCU\..\Run: [qkmo] C:\PROGRA~1\COMMON~1\qkmo\qkmom.exe
O4 - HKCU\..\Run: [services32] C:\Program Files\Common Files\Windows\mc-110-12-0000079.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-110-12-0000079.exe
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a224.g.akamai.net/7/224/52/2...meInstaller.exe
O16 - DPF: {6B4788E2-BAE8-11D2-A1B4-00400512739B} (PWMediaSendControl Class) - http://216.249.25.152/code/PWActiveXImgCtl.CAB
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\ZGVmYXVsdAAA\command.exe



= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


Locate and delete the following folder(s), if present:
  • C:\WINDOWS\ZGVmYXVsdAAA\
    C:\Program Files\DNS\
    C:\PROGRA~1\COMMON~1\qkmo\
Locate and delete the following file(s), if present:
  • C:\WINDOWS\system32\n20050308.EXE

    C:\WINDOWS\system32\medgs1.exe
    C:\WINDOWS\system32\opr.exe
    C:\Program Files\Common Files\Windows\mc-110-12-0000079.exe
    C:\Program Files\Common Files\mc-110-12-0000079.exe
Search for & delete ... using Start> Search... the following file(s), if present:

  • snmtview.exe
    smbpol.exe

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =


REBOOT TO NORMAL MODE

Do an online scan at one of the following sites:Take note the names and locations of any file it detects but fails to clean.
* Turn off the real time scanner of any existing antivirus program while performing the online scan


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

In your next post, please include fresh logs from:
  1. HiJackThis
  2. TMAS results/ 'Antispyware.log'
  3. Online scan
Please provide details of any problems you encountered whilst performing the above steps & update us on how the computer behaves now
__________________


POADB is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 09-04-2005, 12:46 AM   #3 (permalink)
Registered User
 
Join Date: Sep 2005
Posts: 6
OS: WinXP


Thanks for your response! I followed your instructions, most were fine though I could not locate "Internet Explorer Web Content Catcher" in Add/Remove Programs. There were also a few files on HiJackThis that were not there, specifically the second and last ones listed. Also "mc-110-12-0000079.exe" did not exist in Program Files\Common Files but instead in System32.

Right now the non-stop pop-ups have ceased (yay!). I have included below my current HiJackThis, TMAS results, and Kaspersky online scan.

Logfile of HijackThis v1.99.1
Scan saved at 2:34:15 AM, on 9/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\TrojanHunter 4.2\THGuard.exe
C:\DOCUME~1\default\LOCALS~1\Temp\InSearch.exe
C:\PROGRA~1\MESSEN~1\msmsgs.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
C:\Program Files\Common Files\efax\Dllcmd32.exe
C:\Program Files\Common Files\efax\HotTray.exe
C:\Program Files\MTV Networks\VOpt\MTVOptTray.exe
C:\Program Files\MTV Networks\VOpt\MTVOptQueue.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [%%DELETE_VALUE%%] CreateCD50
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [Windows Incontext] C:\DOCUME~1\default\LOCALS~1\Temp\InSearch.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\PROGRA~1\MESSEN~1\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
O4 - Global Startup: Camio Viewer 3.2.lnk = C:\Program Files\Sierra Imaging\Image Expert 2000\IXApplet.exe
O4 - Global Startup: Live Menu.lnk = C:\Program Files\Common Files\efax\Dllcmd32.exe
O4 - Global Startup: eFax.com Tray Menu.lnk = C:\Program Files\Common Files\efax\HotTray.exe
O4 - Global Startup: America Online 7.0 Tray Icon.lnk = C:\Program Files\America Online 7.0\aoltray.exe
O4 - Global Startup: MTV Networks Video Optimizer.lnk = C:\Program Files\MTV Networks\VOpt\MTVOptTray.exe
O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra 'Tools' menuitem: Encarta Encyclopedia - {2FDEF853-0759-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
O9 - Extra button: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra 'Tools' menuitem: Define - {5DA9DE80-097A-11D4-A92E-006097DBED37} - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://education.dellnet.com/ (file missing) (HKCU)
O16 - DPF: Yahoo! PagerLite - http://jpager.yahoo.com/m6/msgr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/k...an_unicode.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {CE74A05D-ED12-473A-97F8-85FB0E2F479F} (dlControl.UserControl1) - https://stores.musictoday.com/store/...ugsActiveX.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite...ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {FCEAE646-DCF9-4D59-B994-6BD30A315139} - http://www.mtv.com/overdrive/bin/setup.exe
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/...ampx_en_dl.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

Online Scan:

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Sunday, September 04, 2005 02:31:43
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 4/09/2005
Kaspersky Anti-Virus database records: 138802
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 90400
Number of viruses found: 4
Number of infected objects: 16
Number of suspicious objects: 0
Duration of the scan process: 3124 sec

Infected Object Name - Virus Name
C:\Documents and Settings\default\Local Settings\Temporary Internet Files\Content.IE5\C1EFW1UZ\stats6[1].htm Infected: Exploit.HTML.Mht
C:\Documents and Settings\default\Local Settings\Temporary Internet Files\Content.IE5\JH7COKEY\track10[1].htm Infected: Exploit.HTML.Mht
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057371.dll Infected: Trojan-Downloader.Win32.Qoologic.ad
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057374.dll Infected: Trojan-Downloader.Win32.Qoologic.ad
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057375.cpl Infected: Trojan-Downloader.Win32.Qoologic.ad
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057377.exe/WISE0007.BIN Infected: Trojan-Downloader.Win32.TSUpdate.j
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057377.exe Infected: Trojan-Downloader.Win32.TSUpdate.j
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057378.exe/data0026/bdeviewer.exe Infected: Trojan.Win32.Krepper.y
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057378.exe/data0026 Infected: Trojan.Win32.Krepper.y
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057378.exe Infected: Trojan.Win32.Krepper.y
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057379.exe/data0030/bdeviewer.exe Infected: Trojan.Win32.Krepper.y
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057379.exe/data0030 Infected: Trojan.Win32.Krepper.y
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057379.exe Infected: Trojan.Win32.Krepper.y
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057380.exe/data0027/bdeviewer.exe Infected: Trojan.Win32.Krepper.y
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057380.exe/data0027 Infected: Trojan.Win32.Krepper.y
C:\System Volume Information\_restore{64A35884-4EAC-496B-B1EA-DF7677605F7E}\RP767\A0057380.exe Infected: Trojan.Win32.Krepper.y

Scan process completed.

Continued in next post...
iambaytor is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Old 09-04-2005, 12:53 AM   #4 (permalink)
Registered User
 
Join Date: Sep 2005
Posts: 6
OS: WinXP


Here is part 1 of TMAS results (too big for one post, yikes!):

Started Scanning
Internet Cookies
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'media.top-banners.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'partypoker.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'tickle.com' in 'Internet Explorer Cache'
Found 'qksrv.net' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'zedo.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'ads.pointroll.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'tribalfusion.com' in 'Internet Explorer Cache'
Found 'edge.ru4.com' in 'Internet Explorer Cache'
Found 'server.iad.liveperson.net' in 'Internet Explorer Cache'
Found '2o7.net' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'partypoker.touchclarity.com' in 'Internet Explorer Cache'
Found 'as-us.falkag.net' in 'Internet Explorer Cache'
Found 'maxserving.com' in 'Internet Explorer Cache'
Found 'serving-sys.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'ad.yieldmanager.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'azjmp.com' in 'Internet Explorer Cache'
Found 'media.adrevolver.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.accoona.com' in 'Internet Explorer Cache'
Found 'bfast.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'bluestreak.com' in 'Internet Explorer Cache'
Found 'banners.searchingbooth.com' in 'Internet Explorer Cache'
Found 'fastclick.net' in 'Internet Explorer Cache'
Found 'apmebf.com' in 'Internet Explorer Cache'
Found 'adopt.specificclick.net' in 'Internet Explorer Cache'
Found 'a.websponsors.com' in 'Internet Explorer Cache'
Found 'dist.belnk.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'casalemedia.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'hits.clickandtrack.net' in 'Internet Explorer Cache'
Found 'hypertracker.com' in 'Internet Explorer Cache'
Found 'questionmarket.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'z1.adserver.com' in 'Internet Explorer Cache'
Found 'ads.addynamix.com' in 'Internet Explorer Cache'
Found 'ads.addynamix.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'valuead.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'hc2.humanclick.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'trafficmp.com' in 'Internet Explorer Cache'
Found 'hc2.humanclick.com' in 'Internet Explorer Cache'
Found 'commission-junction.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'adknowledge.com' in 'Internet Explorer Cache'
Found 'revenue.net' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'belnk.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'realmedia.com' in 'Internet Explorer Cache'
Programs in Memory
Windows Registry
Found '' in 'SOFTWARE\iMesh'
Found '' in 'Software\Kazaa'
Found '' in 'Software\Kazaa\ResultsFilter'
Found '' in 'Software\Kazaa\Settings'
Found '' in 'Software\Kazaa\Transfer'
Found '' in 'Software\KaZaA\CloudLoad'
Found '' in 'Software\KaZaA\ConnectionInfo'
Found '' in 'Software\KaZaA\LocalContent'
Found '' in 'Software\Gnucleus\Searches'
Found '' in 'Software\Microsoft\Windows\CurrentVersion\Uninstall\Morpheus Preview Edition'
Found '' in 'Software\iMesh\Client'
Found '' in 'Software\iMesh\Client\LocalContent'
Found '' in 'Software\iMesh\Client\SOCKS'
Found '' in 'Software\iMesh\Client\Transfer'
Found '' in 'SOFTWARE\Classes\.imesh'
Found '' in 'SOFTWARE\Classes\.imusr'
Found '' in 'SOFTWARE\Classes\IMESH.Document'
Found '' in 'SOFTWARE\Classes\iMeshClient.DocHostUIHandler'
Found '' in 'SOFTWARE\Classes\iMeshClient.DocHostUIHandler\Clsid'
Found '' in 'SOFTWARE\Classes\IMUSR.Document'
Found '' in 'SOFTWARE\Classes\IMUSR.Document\shell\open\command'
Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iMesh'
Found '' in 'Software\Kazaa'
Found '' in 'Software\Kazaa\Advanced'
Found '' in 'Software\Kazaa\Channels\AIRARENA_BROWSE'
Found '' in 'Software\Kazaa\Channels\DATING'
Found '' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found '' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found '' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found '' in 'Software\Kazaa\Channels\P2P'
Found '' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found '' in 'Software\Kazaa\Channels\WEBSEARCH'
Found '' in 'Software\Kazaa\DontShow'
Found '' in 'Software\Kazaa\InstantMessaging'
Found '' in 'Software\Kazaa\LocalContent'
Found '' in 'Software\Kazaa\Skins'
Found '' in 'Software\Kazaa\UserDetails'
Found '' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found '' in 'SOFTWARE\Kazaa\Bandwidth\LastEstimate'
Found '' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\D:\InstallShield\Kazaa\kazaa.exe'
Found '' in 'Software\iMesh'
Found '' in 'SOFTWARE\iMesh\Client'
Found '' in 'SOFTWARE\iMesh\Client\ConnectionInfo'
Found '' in 'SOFTWARE\iMesh\Client\Local'
Found '' in 'SOFTWARE\iMesh\Client\LocalContent'
Found '' in 'SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32'
Found '' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found '' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found '' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found '' in 'SOFTWARE\Magnet'
Found '' in 'SOFTWARE\Magnet\Handlers\Kazaa'
Found '' in 'SOFTWARE\Magnet\Handlers\Kazaa\Type'
Found '' in 'SOFTWARE\Classes\magnet'
Found '' in 'SOFTWARE\Classes\magnet\shell\open\command'
Found '' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'Location' in 'SOFTWARE\Magnet'
Found 'LastSearchHash' in 'Software\Kazaa'
Found 'Tmp' in 'Software\Kazaa'
Found 'ScanFolder' in 'Software\Kazaa\Advanced'
Found 'ScWeeklyDate' in 'Software\Kazaa\Advanced'
Found 'Status' in 'Software\Kazaa\Advanced'
Found '' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'ChannelFile' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'ChannelType' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'DisplayName' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'IconFile' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'IconPath' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'IconServer' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'Mandatory' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'NotAdded' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'Position' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'Source' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'SsmUrl' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'TargetUrl' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'Uninstalled' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'Visible' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'ChannelFile' in 'Software\Kazaa\Channels\DATING'
Found 'ChannelType' in 'Software\Kazaa\Channels\DATING'
Found 'DisplayName' in 'Software\Kazaa\Channels\DATING'
Found 'IconFile' in 'Software\Kazaa\Channels\DATING'
Found 'IconPath' in 'Software\Kazaa\Channels\DATING'
Found 'IconServer' in 'Software\Kazaa\Channels\DATING'
Found 'Mandatory' in 'Software\Kazaa\Channels\DATING'
Found 'NotAdded' in 'Software\Kazaa\Channels\DATING'
Found 'Position' in 'Software\Kazaa\Channels\DATING'
Found 'Source' in 'Software\Kazaa\Channels\DATING'
Found 'SsmUrl' in 'Software\Kazaa\Channels\DATING'
Found 'TargetUrl' in 'Software\Kazaa\Channels\DATING'
Found 'Uninstalled' in 'Software\Kazaa\Channels\DATING'
Found 'Visible' in 'Software\Kazaa\Channels\DATING'
Found 'ChannelFile' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'ChannelType' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'DisplayName' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'IconFile' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'IconPath' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'IconServer' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'Mandatory' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'NotAdded' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'Position' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'Source' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'SsmUrl' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'TargetUrl' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'Uninstalled' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'Visible' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'ChannelFile' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'ChannelType' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'DisplayName' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'IconFile' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'IconPath' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'IconServer' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'Mandatory' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'NotAdded' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'Position' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'Source' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'SsmUrl' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'TargetUrl' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'Uninstalled' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'Visible' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'ChannelFile' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'ChannelType' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'DisplayName' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'IconFile' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'IconPath' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'IconServer' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'Mandatory' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'NotAdded' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'Position' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'Source' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'SsmUrl' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'TargetUrl' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'Uninstalled' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'Visible' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'ChannelFile' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'ChannelType' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'DisplayName' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'IconFile' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'IconPath' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'IconServer' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'Mandatory' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'NotAdded' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'Position' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'Source' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'SsmUrl' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'TargetUrl' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'Uninstalled' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'Visible' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'ChannelFile' in 'Software\Kazaa\Channels\P2P'
Found 'ChannelType' in 'Software\Kazaa\Channels\P2P'
Found 'DisplayName' in 'Software\Kazaa\Channels\P2P'
Found 'IconFile' in 'Software\Kazaa\Channels\P2P'
Found 'IconPath' in 'Software\Kazaa\Channels\P2P'
Found 'IconServer' in 'Software\Kazaa\Channels\P2P'
Found 'Mandatory' in 'Software\Kazaa\Channels\P2P'
Found 'NotAdded' in 'Software\Kazaa\Channels\P2P'
Found 'Position' in 'Software\Kazaa\Channels\P2P'
Found 'Source' in 'Software\Kazaa\Channels\P2P'
Found 'SsmUrl' in 'Software\Kazaa\Channels\P2P'
Found 'TargetUrl' in 'Software\Kazaa\Channels\P2P'
Found 'Uninstalled' in 'Software\Kazaa\Channels\P2P'
Found 'Visible' in 'Software\Kazaa\Channels\P2P'
Found 'ChannelFile' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'ChannelType' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'DisplayName' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'IconFile' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'IconPath' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'IconServer' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'Mandatory' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'NotAdded' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'Position' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'Source' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'SsmUrl' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'TargetUrl' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'Uninstalled' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'Visible' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'ChannelFile' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'ChannelType' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'DisplayName' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'IconFile' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'IconPath' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'IconServer' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'Mandatory' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'NotAdded' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'Position' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'Source' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'SsmUrl' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'TargetUrl' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'Uninstalled' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'Visible' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found 'ChannelFile' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'ChannelType' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'DisplayName' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'IconFile' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'IconPath' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'IconServer' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'Mandatory' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'NotAdded' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'Position' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'Source' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'SsmUrl' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'TargetUrl' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'Uninstalled' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'Visible' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found 'ChannelFile' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'ChannelType' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'DisplayName' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'IconFile' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'IconPath' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'IconServer' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'Mandatory' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'NotAdded' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'Position' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'Source' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'SsmUrl' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'TargetUrl' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'Uninstalled' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'Visible' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'ChannelFile' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'ChannelType' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'DisplayName' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'IconFile' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'IconPath' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'IconServer' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'Mandatory' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'NotAdded' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'Position' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'Source' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'SsmUrl' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'TargetUrl' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'Uninstalled' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'Visible' in 'Software\Kazaa\Channels\WEBSEARCH'
Found 'CloseToSystray' in 'Software\Kazaa\DontShow'
Found 'IgnoreAll' in 'Software\Kazaa\InstantMessaging'
Found '' in 'Software\Kazaa\Kazaa\Download Width'
Found '' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '0' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '1' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '10' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '11' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '12' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '2' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '3' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '4' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '5' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '6' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '7' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '8' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '9' in 'Software\Kazaa\Kazaa\EverythingWidth'
Found '' in 'Software\Kazaa\Kazaa\MyKazaaStates'
Found 'My Kapsules' in 'Software\Kazaa\Kazaa\MyKazaaStates'
Found 'My Media' in 'Software\Kazaa\Kazaa\MyKazaaStates'
Found 'My Playlists' in 'Software\Kazaa\Kazaa\MyKazaaStates'
Found '' in 'Software\Kazaa\Kazaa\Settings'
Found 'SACol1' in 'Software\Kazaa\Kazaa\Settings'
Found 'SACol2' in 'Software\Kazaa\Kazaa\Settings'
Found 'SACol3' in 'Software\Kazaa\Kazaa\Settings'
Found 'WindowPos' in 'Software\Kazaa\Kazaa\Settings'
Found 'ChannelsDir' in 'Software\Kazaa\LocalContent'
Found 'DisableListFiles' in 'Software\Kazaa\LocalContent'
Found 'SearchAgents' in 'Software\Kazaa\LocalContent'
Found '' in 'Software\Kazaa\Search'
Found 'adult_filter_level' in 'Software\Kazaa\ResultsFilter'
Found 'b' in 'SOFTWARE\Kazaa\Bandwidth\LastEstimate'
Found 'b0' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found 'b0' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found 'b0seconds' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found 'b0seconds' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found 'b1' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found 'b1' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found 'CacheDiscoveryTime' in 'Software\Kazaa\Transfer'
Found 'CacheHost' in 'Software\Kazaa\Transfer'
Found 'CachePort' in 'Software\Kazaa\Transfer'
Found 'CountryCode' in 'Software\Kazaa\UserDetails'
Found 'DatabaseDir' in 'SOFTWARE\Kazaa\LocalContent'
Found 'Date' in 'Software\Kazaa\Settings'
Found 'DdeApplication' in 'SOFTWARE\Magnet\Handlers\Kazaa'
Found 'DdeTopic' in 'SOFTWARE\Magnet\Handlers\Kazaa'
Found 'DlDir0' in 'Software\Kazaa\Transfer'
Found 'DownloadDir' in 'SOFTWARE\Kazaa\LocalContent'
Found 'AutoConnected' in 'Software\Kazaa\UserDetails'
Found 'Description' in 'SOFTWARE\Magnet\Handlers\Kazaa'
Found 'firewall_filter' in 'Software\Kazaa\ResultsFilter'
Found 'HelpDir' in 'Software\Kazaa\Settings'
Found 'Quarantine' in 'Software\Kazaa\Settings'
Found 'SearchDir' in 'Software\Kazaa\Settings'
Found 'UseCount' in 'Software\Kazaa\Settings'
Found 'SkinsDir' in 'Software\Kazaa\Skins'
Found 'NoUploadLimitWhenIdle' in 'Software\Kazaa\Transfer'
Found 'UserName' in 'Software\Kazaa\UserDetails'
Found 'FirewallStatus' in 'SOFTWARE\Kazaa'
Found 'ListenPort' in 'SOFTWARE\Kazaa'
Found 'my_ip_address' in 'SOFTWARE\Kazaa'
Found 'network_config' in 'SOFTWARE\Kazaa'
Found 'Tmp' in 'SOFTWARE\Kazaa'
Found 'UDP_probe_successes' in 'SOFTWARE\Kazaa'
Found 'UDP_receive_status' in 'SOFTWARE\Kazaa'
Found 'time' in 'SOFTWARE\Kazaa\Bandwidth\LastEstimate'
Found 'ShareDir' in 'SOFTWARE\Kazaa\CloudLoad'
Found 'KazaaNet' in 'SOFTWARE\Kazaa\ConnectionInfo'
Found 'kt' in 'SOFTWARE\Magnet\Handlers\Kazaa'
Found 'ShellExecute' in 'SOFTWARE\Magnet\Handlers\Kazaa'
Found 'http' in 'SOFTWARE\Magnet\Handlers\Kazaa\Type'
Found 'urn:kzhash' in 'SOFTWARE\Magnet\Handlers\Kazaa\Type'
Found 'urn:topsearch' in 'SOFTWARE\Magnet\Handlers\Kazaa\Type'
Found '' in 'Software\AppConf'
Found 'confset' in 'Software\AppConf'
Found '' in 'Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\Range1'
Found '' in 'Software\Dynamic Toolbar'
Found '' in 'Software\Gnucleus'
Internet URL Shortcuts
Found 'Betting.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Fun & Games\'
Found 'Casino.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Fun & Games\'
Found 'Casino Palace.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Fun & Games\'
Found 'Games.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Fun & Games\'
Found 'Horoscope.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Fun & Games\'
Found 'Air Tickets.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Going Places\'
Found 'Car Rentals.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Going Places\'
Found 'Hotel Deals.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Going Places\'
Found 'Luggage.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Going Places\'
Found 'Travel.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Going Places\'
Found 'Auctions.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Shop\'
Found 'Books.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Shop\'
Found 'Computers.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Shop\'
Found 'Discount.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Shop\'
Found 'Flowers.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Shop\'
Found 'Golf.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Shop\'
Found 'Jewelry.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Shop\'
Found 'Movies.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Shop\'
Found 'Music.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Shop\'
Found 'Online Store.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Shop\'
Found 'Perfume.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Shop\'
Found 'Sleepwear.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Shop\'
Found 'Adware Remover.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Technology\'
Found 'Anti-Virus.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Technology\'
Found 'PC Cleaner.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Technology\'
Found 'Tech & gadgets.lnk' in 'C:\Documents and Settings\default\Favorites\Living\Technology\'
Files and Directories
Found 'dman4.dll' in 'C:\WINDOWS\SYSTEM32'
Found 'BDEInstallProgress4.dll' in 'C:\WINDOWS\SYSTEM32'
Found 'P2P Networking v124.cpl' in 'C:\WINDOWS\SYSTEM32'
Found 'bbshortcut.ico' in 'C:\WINDOWS'
Found '' in 'C:\Program Files\Morpheus'
Found '' in 'C:\Program Files\Morpheus\My Shared Folder'
Found 'Audio - Electronica.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'Audio - Fine Arts Militia Album.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'Audio - Folk.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'Audio - Funk.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'Audio - Hip Hop.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'Audio - Jazz.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'Audio - Pop Rock.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'Audio - Public Enemy Revolverlution Album.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'Audio - R&B.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'Audio - Reggae.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'Audio - The Honey Palace Album.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'Audio - Alternative Rock.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found 'Audio - Barrington Levy.kpl' in 'C:\Program Files\KaZaA\My Shared Folder'
Found '' in 'C:\Program Files\KaZaA\Db'
Found 'bb2.db' in 'C:\Program Files\KaZaA\Db'
Found 'broadband.gif' in 'C:\Program Files\KaZaA\Db'
Found 'broadband2.gif' in 'C:\Program Files\KaZaA\Db'
Found 'kmd.exe' in 'C:\Program Files\KaZaA'
Found '' in 'C:\Program Files\KaZaA\My Channels\Bin'
Found 'dating.kcd' in 'C:\Program Files\KaZaA\My Channels\Bin'
Found 'g_spot.kcd' in 'C:\Program Files\KaZaA\My Channels\Bin'
Found 'onelove_browse.kcd' in 'C:\Program Files\KaZaA\My Channels\Bin'
Found 'rshiphop.kcd' in 'C:\Program Files\KaZaA\My Channels\Bin'
Found 'ringtonechannel.kcd' in 'C:\Program Files\KaZaA\My Channels\Bin'
Found 'emerging_artists.kcd' in 'C:\Program Files\KaZaA\My Channels\Bin'
Found 'skilledgames.kcd' in 'C:\Program Files\KaZaA\My Channels\Bin'
Found 'crazyplaygames.kcd' in 'C:\Program Files\KaZaA\My Channels\Bin'
Found '' in 'C:\Program Files\KaZaA\My Channels\Images'
Found 'dating.bmp' in 'C:\Program Files\KaZaA\My Channels\Images'
Found 'g_spot.bmp' in 'C:\Program Files\KaZaA\My Channels\Images'
Found 'onelove_browse.bmp' in 'C:\Program Files\KaZaA\My Channels\Images'
Found 'ringtonechannel.bmp' in 'C:\Program Files\KaZaA\My Channels\Images'
Found 'rshiphop_browse.bmp' in 'C:\Program Files\KaZaA\My Channels\Images'
Found 'emerging_artists.bmp' in 'C:\Program Files\KaZaA\My Channels\Images'
Found 'skilledgames.bmp' in 'C:\Program Files\KaZaA\My Channels\Images'
Found 'crazyplaygames.bmp' in 'C:\Program Files\KaZaA\My Channels\Images'
Found '' in 'C:\Program Files\KaZaA\Help'
Found 'arrow_sml.gif' in 'C:\Program Files\KaZaA\Help'
Found 'background.gif' in 'C:\Program Files\KaZaA\Help'
Found 'h_mykazaa.gif' in 'C:\Program Files\KaZaA\Help'
Found 'h_myMedia.gif' in 'C:\Program Files\KaZaA\Help'
Found 'h_myplaylists.gif' in 'C:\Program Files\KaZaA\Help'
Found 'icon_gold_kap.gif' in 'C:\Program Files\KaZaA\Help'
Found 'myKapsules.gif' in 'C:\Program Files\KaZaA\Help'
Found 'mykapsules.htm' in 'C:\Program Files\KaZaA\Help'
Found 'mykazaa.css' in 'C:\Program Files\KaZaA\Help'
Found 'mykazaa.htm' in 'C:\Program Files\KaZaA\Help'
Found 'mymedia.htm' in 'C:\Program Files\KaZaA\Help'
Found 'myplaylists.htm' in 'C:\Program Files\KaZaA\Help'
Found 'searchbar_download_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_download.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_closetab_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_closetab_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_closetab_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_closetab.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_share_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_share_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_share_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_share.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_moreinfo_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_moreinfo_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_moreinfo_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_moreinfo.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_folders_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_folders_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_folders_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_folders.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_delete_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_delete_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_delete_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mykazaabar_delete.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_volume_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_volume_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_volume_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_volume.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_stop_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_stop_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_stop_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_stop.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_sliderThumb_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_sliderThumb.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_slider.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_prev_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_prev_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_prev_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_prev.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_play_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_play_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_play_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_play.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_pause_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_pause_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_pause_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_pause.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_next_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_next_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_next_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_next.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_addtoplay_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_addtoplay_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_addtoplay_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mediabar_addtoplay.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_web_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_web_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_web_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_web.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_traffic_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_traffic_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_traffic_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_traffic.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_theater_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_theater_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_theater_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_theater.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_tell_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_tell_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_tell_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_tell.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_shop_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_shop_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_shop_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_shop.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_search_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_search_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_search_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_search.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_mykazaa_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_mykazaa_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_mykazaa_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_mykazaa.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_peer_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_peer_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_peer.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'mainbar_peer_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'trafficbar_resume_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'trafficbar_resume_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'trafficbar_resume_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'trafficbar_resume.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'trafficbar_pause_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'trafficbar_pause_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'trafficbar_pause_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'trafficbar_pause.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'trafficbar_cancel_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'trafficbar_cancel_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'trafficbar_cancel_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'trafficbar_cancel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'theatrebar_fullscreen_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'theatrebar_fullscreen_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'theatrebar_fullscreen_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'theatrebar_fullscreen.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_stop_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_stop_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_stop_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_stop.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_refresh_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_refresh_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_refresh_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_refresh.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_home_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_home_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_home_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_home.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_fwd_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_fwd_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_fwd_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_fwd.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_back_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_back_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_back_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'startbar_back.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_showsearch_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_showsearch_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_showsearch_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_showsearch.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_searchuser_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_searchuser_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_searchuser_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_searchuser.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_newsearch_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_newsearch_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_newsearch_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_newsearch.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_messageuser_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_messageuser_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_messageuser_dis.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_messageuser.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_download_sel.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'searchbar_download_over.bmp' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found 'License.txt' in 'C:\Program Files\KaZaA\Skins\Orbital Shadows'
Found '' in 'C:\Program Files\KaZaA\Promotions'
Found 'kmdnew.exe' in 'C:\Program Files\KaZaA'
Found 'broadband2.gif' in 'C:\Program Files\KaZaA'
Found 'broadband.gif' in 'C:\Program Files\KaZaA'
Found '' in 'C:\Program Files\KaZaA\BGP2P'
Found 'bdcore.dll' in 'C:\Program Files\KaZaA\BGP2P'
Found 'bdupd.dll' in 'C:\Program Files\KaZaA'
Found 'Kazaa.exe' in 'C:\Program Files\KaZaA'
Found 'kzscan.dll' in 'C:\Program Files\KaZaA'
Found '' in 'C:\Program Files\WinMX'
Found 'kmd2.exe' in 'C:\Program Files'
Found '' in 'C:\Program Files\MyWay'
Found '' in 'C:\Documents and Settings\default\Start Menu\Programs\Kazaa'
Finished Scanning
Started Scanning
Internet Cookies
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'media.top-banners.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'partypoker.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'tickle.com' in 'Internet Explorer Cache'
Found 'qksrv.net' in 'Internet Explorer Cache'
Found 'zedo.com' in 'Internet Explorer Cache'
Found 'ads.pointroll.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'tribalfusion.com' in 'Internet Explorer Cache'
Found 'edge.ru4.com' in 'Internet Explorer Cache'
Found 'server.iad.liveperson.net' in 'Internet Explorer Cache'
Found '2o7.net' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'partypoker.touchclarity.com' in 'Internet Explorer Cache'
Found 'as-us.falkag.net' in 'Internet Explorer Cache'
Found 'maxserving.com' in 'Internet Explorer Cache'
Found 'serving-sys.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'ad.yieldmanager.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'azjmp.com' in 'Internet Explorer Cache'
Found 'media.adrevolver.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.accoona.com' in 'Internet Explorer Cache'
Found 'bfast.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'bluestreak.com' in 'Internet Explorer Cache'
Found 'banners.searchingbooth.com' in 'Internet Explorer Cache'
Found 'fastclick.net' in 'Internet Explorer Cache'
Found 'apmebf.com' in 'Internet Explorer Cache'
Found 'adopt.specificclick.net' in 'Internet Explorer Cache'
Found 'a.websponsors.com' in 'Internet Explorer Cache'
Found 'dist.belnk.com' in 'Internet Explorer Cache'
Found 'casalemedia.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'hits.clickandtrack.net' in 'Internet Explorer Cache'
Found 'hypertracker.com' in 'Internet Explorer Cache'
Found 'questionmarket.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'z1.adserver.com' in 'Internet Explorer Cache'
Found 'ads.addynamix.com' in 'Internet Explorer Cache'
Found 'ads.addynamix.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'valuead.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'hc2.humanclick.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'trafficmp.com' in 'Internet Explorer Cache'
Found 'hc2.humanclick.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'commission-junction.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'adknowledge.com' in 'Internet Explorer Cache'
Found 'revenue.net' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'www.allthatsearch.com' in 'Internet Explorer Cache'
Found 'belnk.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'www.searchingbooth.com' in 'Internet Explorer Cache'
Found 'realmedia.com' in 'Internet Explorer Cache'
Programs in Memory
Windows Registry
Found '' in 'SOFTWARE\iMesh'
Found '' in 'Software\Kazaa'
Found '' in 'Software\Kazaa\ResultsFilter'
Found '' in 'Software\Kazaa\Settings'
Found '' in 'Software\Kazaa\Transfer'
Found '' in 'Software\KaZaA\CloudLoad'
Found '' in 'Software\KaZaA\ConnectionInfo'
Found '' in 'Software\KaZaA\LocalContent'
Found '' in 'Software\Gnucleus\Searches'
Found '' in 'Software\Microsoft\Windows\CurrentVersion\Uninstall\Morpheus Preview Edition'
Found '' in 'Software\iMesh\Client'
Found '' in 'Software\iMesh\Client\LocalContent'
Found '' in 'Software\iMesh\Client\SOCKS'
Found '' in 'Software\iMesh\Client\Transfer'
Found '' in 'SOFTWARE\Classes\.imesh'
Found '' in 'SOFTWARE\Classes\.imusr'
Found '' in 'SOFTWARE\Classes\IMESH.Document'
Found '' in 'SOFTWARE\Classes\iMeshClient.DocHostUIHandler'
Found '' in 'SOFTWARE\Classes\iMeshClient.DocHostUIHandler\Clsid'
Found '' in 'SOFTWARE\Classes\IMUSR.Document'
Found '' in 'SOFTWARE\Classes\IMUSR.Document\shell\open\command'
Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\iMesh'
Found '' in 'Software\Kazaa'
Found '' in 'Software\Kazaa\Advanced'
Found '' in 'Software\Kazaa\Channels\AIRARENA_BROWSE'
Found '' in 'Software\Kazaa\Channels\DATING'
Found '' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found '' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found '' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found '' in 'Software\Kazaa\Channels\P2P'
Found '' in 'Software\Kazaa\Channels\RSHIPHOP_BROWSE'
Found '' in 'Software\Kazaa\Channels\WEBSEARCH'
Found '' in 'Software\Kazaa\DontShow'
Found '' in 'Software\Kazaa\InstantMessaging'
Found '' in 'Software\Kazaa\LocalContent'
Found '' in 'Software\Kazaa\Skins'
Found '' in 'Software\Kazaa\UserDetails'
Found '' in 'SOFTWARE\Kazaa\Bandwidth\in'
Found '' in 'SOFTWARE\Kazaa\Bandwidth\LastEstimate'
Found '' in 'SOFTWARE\Kazaa\Bandwidth\out'
Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\D:\InstallShield\Kazaa\kazaa.exe'
Found '' in 'Software\iMesh'
Found '' in 'SOFTWARE\iMesh\Client'
Found '' in 'SOFTWARE\iMesh\Client\ConnectionInfo'
Found '' in 'SOFTWARE\iMesh\Client\Local'
Found '' in 'SOFTWARE\iMesh\Client\LocalContent'
Found '' in 'SOFTWARE\Classes\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}\LocalServer32'
Found '' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found '' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found '' in 'Software\Kazaa\Channels\RINGTONECHANNEL_SEARCH'
Found '' in 'SOFTWARE\Magnet'
Found '' in 'SOFTWARE\Magnet\Handlers\Kazaa'
Found '' in 'SOFTWARE\Magnet\Handlers\Kazaa\Type'
Found '' in 'SOFTWARE\Classes\magnet'
Found '' in 'SOFTWARE\Classes\magnet\shell\open\command'
Found '' in 'Software\Kazaa\Channels\SKILLEDGAMES'
Found 'Location' in 'SOFTWARE\Magnet'
Found 'LastSearchHash' in 'Software\Kazaa'
Found 'Tmp' in 'Software\Kazaa'
Found 'ScanFolder' in 'Software\Kazaa\Advanced'
Found 'ScWeeklyDate' in 'Software\Kazaa\Advanced'
Found 'Status' in 'Software\Kazaa\Advanced'
Found '' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'ChannelFile' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'ChannelType' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'DisplayName' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'IconFile' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'IconPath' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'IconServer' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'Mandatory' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'NotAdded' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'Position' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'Source' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'SsmUrl' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'TargetUrl' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'Uninstalled' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'Visible' in 'Software\Kazaa\Channels\CRAZYPLAYGAMES'
Found 'ChannelFile' in 'Software\Kazaa\Channels\DATING'
Found 'ChannelType' in 'Software\Kazaa\Channels\DATING'
Found 'DisplayName' in 'Software\Kazaa\Channels\DATING'
Found 'IconFile' in 'Software\Kazaa\Channels\DATING'
Found 'IconPath' in 'Software\Kazaa\Channels\DATING'
Found 'IconServer' in 'Software\Kazaa\Channels\DATING'
Found 'Mandatory' in 'Software\Kazaa\Channels\DATING'
Found 'NotAdded' in 'Software\Kazaa\Channels\DATING'
Found 'Position' in 'Software\Kazaa\Channels\DATING'
Found 'Source' in 'Software\Kazaa\Channels\DATING'
Found 'SsmUrl' in 'Software\Kazaa\Channels\DATING'
Found 'TargetUrl' in 'Software\Kazaa\Channels\DATING'
Found 'Uninstalled' in 'Software\Kazaa\Channels\DATING'
Found 'Visible' in 'Software\Kazaa\Channels\DATING'
Found 'ChannelFile' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'ChannelType' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'DisplayName' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'IconFile' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'IconPath' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'IconServer' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'Mandatory' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'NotAdded' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'Position' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'Source' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'SsmUrl' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'TargetUrl' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'Uninstalled' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'Visible' in 'Software\Kazaa\Channels\DATING_BROWSE'
Found 'ChannelFile' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'ChannelType' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'DisplayName' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'IconFile' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'IconPath' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'IconServer' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'Mandatory' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'NotAdded' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'Position' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'Source' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'SsmUrl' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'TargetUrl' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'Uninstalled' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'Visible' in 'Software\Kazaa\Channels\EMERGING_ARTISTS_BROWSE'
Found 'ChannelFile' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'ChannelType' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'DisplayName' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'IconFile' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'IconPath' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'IconServer' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'Mandatory' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'NotAdded' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'Position' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'Source' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'SsmUrl' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'TargetUrl' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'Uninstalled' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'Visible' in 'Software\Kazaa\Channels\G_SPOT_BROWSE'
Found 'ChannelFile' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'ChannelType' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'DisplayName' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'IconFile' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'IconPath' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'IconServer' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'Mandatory' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'NotAdded' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'Position' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'Source' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'SsmUrl' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'TargetUrl' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'Uninstalled' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'Visible' in 'Software\Kazaa\Channels\ONELOVE_BROWSE'
Found 'ChannelFile' in 'Software\Kazaa\Channels\P2P'
Found 'ChannelType' in 'Software\Kazaa\Channels\P2P'
Found 'DisplayName' in 'Software\Kazaa\Channels\P2P'
Found 'IconFile' in 'Software\Kazaa\Channels\P2P'
Found 'IconPath' in 'Software\Kazaa\Channels\P2P'
Found 'IconServer' in 'Software\Kazaa\Channels\P2P'
Found 'Mandatory' in 'Software\Kazaa\Channels\P2P'
Found 'NotAdded' in 'Software\Kazaa\Channels\P2P'
Found 'Position' in 'Software\Kazaa\Channels\P2P'
Found 'Source' in 'Software\Kazaa\Channels\P2P'
Found 'SsmUrl' in 'Software\Kazaa\Channels\P2P'
Found 'TargetUrl' in 'Software\Kazaa\Channels\P2P'
Found 'Uninstalled' in 'Software\Kazaa\Channels\P2P'
Found 'Visible' in 'Software\Kazaa\Channels\P2P'
Found 'ChannelFile' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'ChannelType' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'DisplayName' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'IconFile' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'IconPath' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'IconServer' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'Mandatory' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'NotAdded' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'Position' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'Source' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'SsmUrl' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'TargetUrl' in 'Software\Kazaa\Channels\RINGTONECHANNEL_BROWSE'
Found 'Uninstalled' in 'Software\Kazaa\Channels\R