Content Top
DAL Computer Help » Internet Security Help » Spyware, Adware, Viruses and HijackThis Logs » Computer Problems....

Recommended Fix

Click here to fix Windows Errors and Optimize Windows Performance

Need Computer Help?
Register Now for FREE

Computer Problems....

Reply
Thread Tools
Spyware, Adware, Viruses and HijackThis Logs
  #1 (permalink)  
Old 29-09-2006, 06:39 PM
Junior Member
New Recruit
 
Join Date: Nov 2005
Posts: 38
uncleramsay Is a beginner here at D-A-L
Computer Problems....

Hiya,

I have a few problems with my comp at the mo.
I don't think its malware to be honest, but I would feel better if you could help me check that my computer is clean...!

Symptoms:
1. CD Drive does not recognise new CDs or DVDs inserted into the drive. It does list the correct files, and games play correctly etc, but the CD title stays the same as the CD that was in the drive when the computer started up. For this reason, I also don't get any autoplays.

2. I'm having some problems uninstalling a couple of games. Was cleaning up my comp yesterday, and uninstalled a lot of games. All of them did it except Quake 4, and Command and Conquer: Generals. The InstallShield Wizard started, but then just terminated before the uninstall process started. I tried this a few times with the same results.

3. There are a few entries on the Add/Remove Programs List that I can't remove. One is 'My Way Search Assistant'. It does not have any change or remove buttons, so I can't get rid of it.

4. Some of my taskbar icons are not working properly. The Skype one doesn't appear at startup, only when I actually start the program again from the Start Menu. Also, I never get the 'Remove Hardware' icon up when I plug in a USB flash disk.

I have done an Ad-Aware Scan, and my computer is clean.

Here is my HijackThis log...

Logfile of HijackThis v1.99.1
Scan saved at 18:07:36, on 29/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0006)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Skype\Skype.exe
C:\Program Files\Philips\Philips Lime Service\bin\LimeAlive.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Valve\Steam\Steam.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\Go ogleToolbarNotifier.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\AvidSDMService.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\Program Files\LogMeIn\LogMeIn.exe
c:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Philips\Philips Lime Service\bin\Lime.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PhilipsDM] "C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [USB2Check] RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBContr oller
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [PhilipsLime] "C:\Program Files\Philips\Philips Lime Service\bin\LimeAlive.exe"
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Valve\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\Go ogleToolbarNotifier.exe
O4 - HKCU\..\Run: [µTorrent] "C:\Program Files\uTorrent\utorrent.exe"
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/...gameloader.cab
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com/support/plugins/ebraryRdr.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - https://support.euro.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?Link...04&clcid=0x409
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://dominomail.salvationarmy.org.uk/iNotes6W.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1133473732375
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://eu-housecall.trendmicro-europ...vex/hcImpl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/sof...iveXPlugin.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {BF3FF9A2-AC03-40A1-BA0F-F31076325AA7} - https://dominomail.salvationarmy.org.uk/DHTMLED.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...l/SymAData.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://pc.mywebexpc.com/client/v_my...ra/ieatgpc.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Avid SDM Service (AvidSDMService) - Avid Technology, Inc. - C:\WINDOWS\system32\AvidSDMService.exe
O23 - Service: Avid Startup (AvidStartup) - Unknown owner - C:\WINDOWS\system32\AvidStartup.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

Any help you can give me I would greatly appreciate!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 30-09-2006, 06:41 PM
Neal's Avatar
Senior Member
 
Join Date: Sep 2005
Posts: 5,524
Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!
Re: Computer Problems....

Hi,

Log looks ok.





Download and install
Ewido anti-spyware
4.0
(uninstall any previous version first).
  • Click the Download BUTTON. On the next page click the
    Download now BUTTON.
  • Save and then install (Run) from the save location.
  • Open/Run ewido anti-spyware
  • Wait a few moments and Ewido should Auto update itself (note date of last
    update). If it doesn't update, click the update ICON at top of
    screen:

    Quote:
  • Click on the Update now LINK at the top of the window
    • Click on the Start update button
    • Wait for the update to download and install
  • This is very important to get the LATEST
    updates

  • Click on the Status ICON
    • Under "Your computers Security"
      Click change status on Resident shield to inactive
      (ONLY consider activation of that feature once you are
      clean)
  • Click on the Scanner ICON at the top of the window
  • Click on the Settings tab then select Recommended Actions
    and choose Quarantine




Close ALL open Windows / Programs / Folders. Please start
Ewido, and run a full scan:
  • Click on the default Status ICON and select
    the Scan now LINK.

    OR

  • Click on the Scanner ICON . Select the Scan
    TAB.

    • Select Complete System Scan. Ewido will now begin to scan your
      system.

  • If Ewido finds anything it will list them in the Preview WINDOW:
    • Make sure that Set all elements to: shows
      Quarantine, if not click on the link and choose
      Quarantine from the popup menu.
    • Select Apply all actions at the bottom of the window (and the
      items found will be quarantined - and recoverable, if any items are needed
      back).

  • When the scan has completed, click on the Save Scan Report button
    and save the scan to your Desktop where it can be easily found.
  • Copy and paste the EWIDO scan results into your next
    post.
  • Close Ewido.




Download, install and scan with the 15-day free trial of Sunbelt CounterSpy.
CounterSpy User Guide.
1. When Counterspy completes its scan, the "Scan Results" box will appear.
2. Click on "View Results".
3.Under (Recommended Action), using the drop down menu arrows at the side of each entry found, set EVERYTHING to "Remove".
4. Click on "Take Action".
5. Once everything has been removed, click on "View Details".
6. Copy and Paste the details into a text document and save it to your desktop.
7. Exit Counterspy and post the results in your next reply.
__________________
Stalking and killing Spyware

Have we helped you? Please consider a donation to help keep D-A-L free. Click on donate below



MALWARE: READ FIRST Procedures:
|_ SpyBot V1.5 _|_ HijackThis Log __V2.0.2 _|




ASAP: promoting a high standard and quality of security support no matter where you seek help.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 01-10-2006, 01:24 AM
Junior Member
New Recruit
 
Join Date: Nov 2005
Posts: 38
uncleramsay Is a beginner here at D-A-L
Re: Computer Problems....

Ewido Results...

---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 11:19:22 30/09/2006

+ Scan result:



HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKU\S-1-5-21-1300843200-528733203-3098348463-1005\Software\Microsoft\Windows\CurrentVersion\Ext \Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@bulldog.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@cneteurope.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@metacafe.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@microsoftuk.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@rotator.adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@adtech[2].txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@ad1.clickhype[3].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@clickhype[1].txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@cz3.clickzs[2].txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@com[1].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@e-2dj6wfk4sjajalq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@e-2dj6wfkicjdjkhq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@media.fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@c.goclick[2].txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@hypertracker[2].txt -> TrackingCookie.Hypertracker : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@data4.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined).
:mozilla.9:C:\Documents and Settings\Dale\Application Data\Mozilla\Firefox\Profiles\9vv8a6sd.default\coo kies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@yadro[2].txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\Dale\Cookies\dale@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Program Files\Microsoft Visual Studio\Common\Tools\BIND.EXE -> Trojan.Small : Cleaned with backup (quarantined).


::Report end



CounterSpy Results...

Spyware Scan Details
Start Date: 30/09/2006 23:48:04
End Date: 01/10/2006 01:15:59
Total Time: 1 hrs 27 mins 55 secs

Detected spyware

Messenger Plus! Adware Bundler more information...
Details: Messenger Plus! is a add-on for MSN Messenger. Messenger Plus! installs an OPTIONAL adware called C2Media which is also known as LOP.com.
Status: Deleted

Infected files detected
c:\program files\messenger plus! live\msgpluslive.dll
c:\program files\messenger plus! live\detoured.dll
c:\program files\messenger plus! live\msgplusliveres.dll
c:\program files\messenger plus! live\mpscripts.dll
c:\program files\messenger plus! live\scripts\stealdp\scriptinfo.xml
c:\program files\messenger plus! live\scripts\stealdp\stealdp.js
c:\program files\messenger plus! live\events style sheet.xsl
c:\program files\messenger plus! live\lame_enc.dll
c:\program files\messenger plus! live\libsndfile.dll
c:\program files\messenger plus! live\log viewer.exe
c:\program files\messenger plus! live\mptools.exe
c:\program files\messenger plus! live\uninstall.exe
c:\program files\messenger plus! live\languages\lng_catalan.ini
c:\program files\messenger plus! live\languages\lng_chinesesimplified.ini
c:\program files\messenger plus! live\languages\lng_chinesetraditional.ini
c:\program files\messenger plus! live\languages\lng_danish.ini
c:\program files\messenger plus! live\languages\lng_default.ini
c:\program files\messenger plus! live\languages\lng_dutch.ini
c:\program files\messenger plus! live\languages\lng_estonian.ini
c:\program files\messenger plus! live\languages\lng_finnish.ini
c:\program files\messenger plus! live\languages\lng_french.ini
c:\program files\messenger plus! live\languages\lng_german.ini
c:\program files\messenger plus! live\languages\lng_hungarian.ini
c:\program files\messenger plus! live\languages\lng_italian.ini
c:\program files\messenger plus! live\languages\lng_japanese.ini
c:\program files\messenger plus! live\languages\lng_korean.ini
c:\program files\messenger plus! live\languages\lng_norwegian.ini
c:\program files\messenger plus! live\languages\lng_portuguese.ini
c:\program files\messenger plus! live\languages\lng_spanish.ini
c:\program files\messenger plus! live\languages\lng_thai.ini
c:\documents and settings\dale\my documents\my chat logs\amyhaskew2211@hotmail.com.txt
c:\documents and settings\dale\my documents\my chat logs\ben.jackson@hotmail.co.uk.txt
c:\documents and settings\dale\my documents\my chat logs\domdiddlydom@aol.com.txt
c:\documents and settings\dale\my documents\my chat logs\fayeivory@hotmail.com.txt
c:\documents and settings\dale\my documents\my chat logs\jogill85@hotmail.co.uk.txt
c:\documents and settings\dale\my documents\my chat logs\jude_fox_4@hotmail.com.txt
c:\documents and settings\dale\my documents\my chat logs\mariatoon2806@yahoo.co.uk.txt
c:\documents and settings\dale\my documents\my chat logs\richardcook@hotmail.co.uk.txt
c:\documents and settings\dale\my documents\my chat logs\samwiles@hotmail.co.uk.txt
c:\documents and settings\dale\my documents\my chat logs\the_strange_1_@hotmail.com.txt
c:\documents and settings\dale\my documents\my chat logs\whitinggemma@hotmail.com.txt
c:\documents and settings\dale\my documents\my chat logs\august 2006\amyhaskew2211@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\august 2006\ash_london89@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\august 2006\ben.jackson@hotmail.co.uk.ple
c:\documents and settings\dale\my documents\my chat logs\august 2006\clairuscanerus@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0485.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0501.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0505.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0509.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0546.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0578.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0640.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0687.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0713.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0719.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0724.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0738.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0813.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img0927.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img1008.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img1035.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img1182.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\images\msgplus_img1662.png
c:\documents and settings\dale\my documents\my chat logs\august 2006\incy_wincy_spiderr@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\august 2006\leoxstryker@yahoo.com.ple
c:\documents and settings\dale\my documents\my chat logs\august 2006\pauljames87@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\august 2006\rjwright16@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\august 2006\smarterchild@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\august 2006\the_strange_1_@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\july 2006\clairuscanerus@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\july 2006\davidhearn_1@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0175.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0259.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0260.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0485.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0500.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0504.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0566.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0663.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0669.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0686.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0687.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0703.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0719.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0738.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0740.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img0745.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img1042.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img1203.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img1212.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img1215.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img1247.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\images\msgplus_img1662.png
c:\documents and settings\dale\my documents\my chat logs\july 2006\incy_wincy_spiderr@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\july 2006\leoxstryker@yahoo.com.ple
c:\documents and settings\dale\my documents\my chat logs\july 2006\lilbud86@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\july 2006\pauljames87@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\july 2006\richardcook@hotmail.co.uk.html
c:\documents and settings\dale\my documents\my chat logs\july 2006\smarterchild@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\july 2006\the_strange_1_@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\july 2006\tristan_me@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\july 2006\uncleramsay@hotmail.com.html
c:\documents and settings\dale\my documents\my chat logs\june 2006\becky.carter@hotmail.co.uk.ple
c:\documents and settings\dale\my documents\my chat logs\june 2006\clairuscanerus@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\june 2006\goldeo@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\june 2006\images\msgplus_img0640.png
c:\documents and settings\dale\my documents\my chat logs\june 2006\images\msgplus_img0663.png
c:\documents and settings\dale\my documents\my chat logs\june 2006\images\msgplus_img0713.png
c:\documents and settings\dale\my documents\my chat logs\june 2006\images\msgplus_img0719.png
c:\documents and settings\dale\my documents\my chat logs\june 2006\images\msgplus_img0738.png
c:\documents and settings\dale\my documents\my chat logs\june 2006\images\msgplus_img1662.png
c:\documents and settings\dale\my documents\my chat logs\june 2006\images\thumbs.db
c:\documents and settings\dale\my documents\my chat logs\june 2006\leoxstryker@yahoo.com.ple
c:\documents and settings\dale\my documents\my chat logs\june 2006\pauljames87@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\june 2006\smarterchild@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\june 2006\tristan_me@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\september 2006\alex_n6499@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\september 2006\becky.carter@hotmail.co.uk.ple
c:\documents and settings\dale\my documents\my chat logs\september 2006\clairuscanerus@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\september 2006\davidhearn_1@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0166.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0175.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0456.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0500.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0501.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0513.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0516.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0529.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0640.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0687.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0719.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0828.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0927.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0945.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0969.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img0997.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img1026.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img1206.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\images\msgplus_img1210.png
c:\documents and settings\dale\my documents\my chat logs\september 2006\incy_wincy_spiderr@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\september 2006\leoxstryker@yahoo.com.ple
c:\documents and settings\dale\my documents\my chat logs\september 2006\lf2687@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\september 2006\michael.sheehan8@btinternet.com.ple
c:\documents and settings\dale\my documents\my chat logs\september 2006\ninebellynick@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\september 2006\rjwright16@hotmail.com.ple
c:\documents and settings\dale\my documents\my chat logs\september 2006\the_strange_1_@hotmail.com.ple

Infected registry entries detected
HKEY_CLASSES_ROOT\MsgPlus.Encrypted
HKEY_CLASSES_ROOT\MsgPlus.Encrypted\DefaultIcon C:\Program Files\Messenger Plus! Live\Log Viewer.exe,1
HKEY_CLASSES_ROOT\MsgPlus.Encrypted\shell\open\com mand "C:\Program Files\Messenger Plus! Live\Log Viewer.exe" /ViewLog="%1"
HKEY_CLASSES_ROOT\MsgPlus.Encrypted Encrypted Log File
HKEY_LOCAL_MACHINE\Software\Patchou
HKEY_LOCAL_MACHINE\Software\Patchou\Messenger Plus! Live AppDir C:\Program Files\Messenger Plus! Live
HKEY_LOCAL_MACHINE\Software\Patchou\Messenger Plus! Live LangDir C:\Program Files\Messenger Plus! Live\Languages
HKEY_LOCAL_MACHINE\Software\Patchou\Messenger Plus! Live InterfacesDir C:\Program Files\Messenger Plus! Live\Interface
HKEY_LOCAL_MACHINE\Software\Patchou\Messenger Plus! Live ScriptsDir C:\Program Files\Messenger Plus! Live\Scripts
HKEY_LOCAL_MACHINE\Software\Patchou\Messenger Plus! Live ResourcesDll MsgPlusLiveRes.dll
HKEY_LOCAL_MACHINE\Software\Patchou\Messenger Plus! Live WorkerDll MsgPlusLive.dll
HKEY_LOCAL_MACHINE\Software\Patchou\Messenger Plus! Live FirstInstallTime
HKEY_LOCAL_MACHINE\Software\Patchou\Messenger Plus! Live SoftwareBuild 4240
HKEY_LOCAL_MACHINE\Software\Patchou\Messenger Plus! Live DefaultLangFile Lng_Default.ini
HKEY_CURRENT_USER\SOFTWARE\Patchou
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\AwlVSbLKh Gsx Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\AwlVSbLKh Gsx LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\BYakoqoyp Oaf Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\BYmgixCgx ZMl Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\BZOxCglOh ZYd Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\CrGwusxAt VIh Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\CrGwusxAt VIh LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\CzQpYchKv XKj Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\DMbNPTLPA wot LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\DMbNPTLPA wot Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\DWyuzJBFQ mej Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\EdXMqoybA wpU Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\EtQsmwbEp REd Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\EtQsmwbEp REd LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\EtQsmwbEp REd LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\FBXGwgeof HTS Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\FDVZBZWak bDC Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\FDVZBZWak bDC LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\FYrKomwzY unS Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\GbDMknQud HUt Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\HRJUdYaku edW Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\HVEuigeof Eqv Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\HYuwvTXIe wbM Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\ImvQkuzCn PCb Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\JCuwtXPTE xPO Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\JCuwtXPTE xPO LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\JFHEiapSr Uqj Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\JFRFZDCzQ mfK Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\JFRFZDCzQ mfK LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\JFYbHCwgq hJI Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\JPHJLHGjO lNA Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\JTMckisxA tLK Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\KdHAwuzCv XKj LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\KdHAwuzCv XKj Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\KejWscakb DPO Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\KgynXKzEb Amr Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\KmdIgiizE qvG Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\MckdLOsct VIn Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\NEunOsxAl NAz Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\NSmpYtDCz Ykp Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\NSmpYtDCz Ykp LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\PCnHGbZWp HGl Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\PCnHGbZWp HGl LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\PCnHGbZWp HGl LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\PCnQsdOgq hJI Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\PUqfDCgxW ibE Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\QbDSyhFJU nFE Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\QbLArXMox JVH LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\QbLArXMox JVH Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\QbTVHLHWo rQd Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\QfRNCgeof HTS Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\QfRNCgeof HTS LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\QnMirPTEa sxI LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\QnMirPTEa sxI Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\QxDOceisc tVU Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\RGglEnEwg xPO Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\RGjRIrGyi zRQ Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\RGjRIrGyi zRQ LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\RPPLQsfDH Sot LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\RPPLQsfDH Sot Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\SfAlUdNMj Iuz Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\SfAlUdNMj Iuz LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\UnMdYvFEb Amr Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\XMlGxRVUr Qch Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\YhYtGwrWt Sej Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\YhYtGwrWt Sej LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\YmnHZRQnM ydO Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\ZEujHLKhY unS Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\ZIkonNLPO zBA Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\ZXREhLDAt LKp Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Contacts\ZXWqjSqvY rJI Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Preferences OldPlusChecked 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Preferences ContactWatchTime
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Preferences FirstStart 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Preferences NotifyAutoUpdate 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Preferences TabChatAuto 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Preferences SoundsAutoPlay 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Preferences LockEnableShortcut 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Preferences EventViewerMaximised 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Preferences EventViewerPos
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\clairuscanerus@hotmail.com\Preferences EventViewerLastShow
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\15A31064C459 Name Matrix - No Spoon
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\15A31064C459 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\15A31064C459 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\15A31064C459 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1674DC9D126A Name Matrix - Nice Trick
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1674DC9D126A Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1674DC9D126A Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1674DC9D126A Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\17429FFF04CE Name Matrix - Not Out Yet
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\17429FFF04CE Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\17429FFF04CE Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\17429FFF04CE Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1C7CC918CA2E Name Matrix - Believe It
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1C7CC918CA2E Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1C7CC918CA2E Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1C7CC918CA2E Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1D61A25F5730 Name Matrix - Skill
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1D61A25F5730 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1D61A25F5730 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1D61A25F5730 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1D61A25F5730 LastUse
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1D61A25F5730 NeedsLoading 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1EFE6AE72ECB Name Matrix - Hit Me
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1EFE6AE72ECB Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1EFE6AE72ECB Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\1EFE6AE72ECB Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\20D2115B70E7 Name Matrix - Kung Fu
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\20D2115B70E7 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\20D2115B70E7 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\20D2115B70E7 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26831598DC08 Name Matrix - Denial
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26831598DC08 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26831598DC08 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26831598DC08 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26B592AFA1EA Name Matrix - Dodge This
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26B592AFA1EA Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26B592AFA1EA Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26B592AFA1EA Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26B8347A48D9 Name Matrix - Believe
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26B8347A48D9 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26B8347A48D9 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26B8347A48D9 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26BC078D301F Name MK - Fight
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26BC078D301F Category 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26BC078D301F Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\26BC078D301F Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2798C1386F24 Name Matrix - Upgrades
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2798C1386F24 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2798C1386F24 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2798C1386F24 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2924F8C760C9 Name Dale - Death
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2924F8C760C9 Category 4
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2924F8C760C9 Flags 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2924F8C760C9 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\29583EBA5C6C Name Matrix Feel Weird
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\29583EBA5C6C Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\29583EBA5C6C Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\29583EBA5C6C Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\295BC062C948 Name Matrix - Welcome
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\295BC062C948 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\295BC062C948 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\295BC062C948 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\295BC062C948 LastUse
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\295BC062C948 NeedsLoading 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2CCC3EA68F60 Name Matrix - At Last
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2CCC3EA68F60 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2CCC3EA68F60 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2CCC3EA68F60 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2CCC3EA68F60 LastUse
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2CCC3EA68F60 NeedsLoading 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2CEFDAE7B26A Name MK - Excellent
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2CEFDAE7B26A Category 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2CEFDAE7B26A Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\2CEFDAE7B26A Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\304A603635C6 Name MK - Well Done
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\304A603635C6 Category 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\304A603635C6 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\304A603635C6 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\30B43310AB7D Name MK - Finish Him
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\30B43310AB7D Category 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\30B43310AB7D Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\30B43310AB7D Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\345C7D09AAC5 Name MK - Fatality
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\345C7D09AAC5 Category 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\345C7D09AAC5 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\345C7D09AAC5 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\34A95CB6FC10 Name MK - Outstanding
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\34A95CB6FC10 Category 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\34A95CB6FC10 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\34A95CB6FC10 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\34F463619C4C Name Matrix - No Return
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\34F463619C4C Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\34F463619C4C Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\34F463619C4C Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\35BE0446594A Name Matrix - Must Get Out
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\35BE0446594A Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\35BE0446594A Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\35BE0446594A Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\35F2309EE9F3 Name Matrix - Aggrevated
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\35F2309EE9F3 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\35F2309EE9F3 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\35F2309EE9F3 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\374D71891C94 Name MK - Laugh
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\374D71891C94 Category 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\374D71891C94 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\374D71891C94 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\389BAE2C79E5 Name Matrix - Desert
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\389BAE2C79E5 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\389BAE2C79E5 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\389BAE2C79E5 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\3F09CC65C7C1 Name MK - Flawless
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\3F09CC65C7C1 Category 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\3F09CC65C7C1 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\3F09CC65C7C1 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\40534CBF1DE8 Name Matrix - Guns
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\40534CBF1DE8 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\40534CBF1DE8 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\40534CBF1DE8 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\45D43DFD89FD Name Matrix - Goodbye
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\45D43DFD89FD Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\45D43DFD89FD Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\45D43DFD89FD Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\4F53A97F72BF Name Matrix - Knew It
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\4F53A97F72BF Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\4F53A97F72BF Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\4F53A97F72BF Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\51604D60EEBA Name Matrix - Blue Pill
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\51604D60EEBA Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\51604D60EEBA Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\51604D60EEBA Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\5E2D81D8900C Name Matrix - FreeYourMind
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\5E2D81D8900C Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\5E2D81D8900C Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\5E2D81D8900C Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\73D06431FDBD Name Matrix - Beginning End
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\73D06431FDBD Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\73D06431FDBD Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\73D06431FDBD Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\7D0B75A651E2 Name Matrix - Hate
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\7D0B75A651E2 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\7D0B75A651E2 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\7D0B75A651E2 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\87B753BB3227 Name Matrix - Dodge Bullets
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\87B753BB3227 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\87B753BB3227 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\87B753BB3227 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\AB3DE90B73D5 Name Matrix - My Name
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\AB3DE90B73D5 Category 2
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\AB3DE90B73D5 Flags 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\CustSounds\AB3DE90B73D5 Language 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\GlobalSettings\Scripts\StealDP Enabled 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\LogViewer PosMaximised 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\LogViewer PosRect
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\AybCyyucrOyb LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\AybCyyucrOyb Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\BXObTFHEzWgj Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\BXObTFHEzWgj LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\CdQkjFCxUofI Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\CdQkjFCxUofI LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\CzREgcklIctW Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\CzREgcklIctW LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\CzREgcklIctW LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\DIvLUdLNWqhQ Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\DIvLUdLNWqhQ LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\DKxKbEnQlIsv Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\DKxKbEnQlIsv LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\DUvXOksvWnDA Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\DUvXOksvWnDA LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\DZPRRNIkshHE Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\DZPRRNIkshHE LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\EpAwjNAadEyp LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\EpAwjNAadEyp Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\EpAwjNAadEyp LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ErVMxEqygvVS Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ErVMxEqygvVS LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\EvIgtLYhDFWh Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\EvIgtLYhDFWh LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ExXEabCelNYv Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ExXEabCelNYv LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FBPJWyucrRBY Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FBPJWyucrRBY LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FBSlAlTQlIsv Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FBSlAlTQlIsv LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FGhSlTQlAulO Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FGhSlTQlAulO LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FMunVSujJUrA Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FMunVSujJUrA LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FNDMtMmuckhY Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FNDMtMmuckhY LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FQanFXNPYpFC Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FQasurYvWnDA Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FRYmyuqynKux Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FRYmyuqynKux LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FSyoknVEvLWr Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FSyoknVEvLWr LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FVGjLSnVSbBY Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FVGjLSnVSbBY LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\FWjHIwehIzPM Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\GjRLUksvWnDA Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\GjRLUksvWnDA LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\GsfBOehIzZKh Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\GsfBOehIzZKh LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\GuouweaixXHE Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\GuouweaixXHE LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HAnDYawetTDA Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HAnDYawetTDA LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HBBWyobCzAul Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HBBWyobCzAul LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HBLXPROjYsjM Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HBLXPROjYsjM LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HBLXPROjYsjM LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HBStXQiqynNK Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HDYhPRNAwpFC LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HDYhPRNAwpFC Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HEksfYylHEor LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HEksfYylHEor Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HEksfYylHEor LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HJSgpPWmpFCf Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HXLYkzCdLMjS Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\HXLYkzCdLMjS LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IbSgpPROjGqt Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IbSgpPROjGqt LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IcsfNYlOjGqt LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IcsfNYlOjGqt Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IjWixMeaixXU Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IjWixMeaixXU LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IkdQqfXZWfFC Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IkdQqfXZWfFC LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IkgjJKaixUeh Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IkgjJKaixUeh LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IklSujRAcsvE Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IklSujRAcsvE LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IkvYovPWygdU Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IyrYlAuckqyp LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\IyrYlAuckqyp Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\JFPJQhGdEvLI Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\JFPJQhGdEvLI LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\KyevBCembBMp Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\KyevBCembBMp LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\LNNWpAcfGxNK Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\LNNWpAcfGxNK LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\LOghOhPMhEor LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\LOghOhPMhEor Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\LOghOhPMhEor LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\LSsibYhNKfFQ Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\LSsibYhNKfFQ LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\NDNKksakqnDQ Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\NQkxTQshEofG Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\NQkxTQshEofG LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\NSjEgeaixUeh Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\NSjEgeaixUeh LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\NSjEgeaixUeh LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\NYhEgcklIctW Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\NYhEgcklIctW LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ObLYbOqtUlBY Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ObLYbOqtUlBY LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OibDVXNPYsil Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OibDVXNPYsil LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OksfRTQlAulO Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OrEfYpEgnPAx Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OrGxSqlOjGqt Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OtXGssuckzZW Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OtXGssuckzZW LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OuapLFVXGxNK Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OuapLFVXGxNK LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OxAvVSulNAcf Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OxAvVSulNAcf LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OxFFVPROjGqt LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OxFFVPROjGqt Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OxFFVPROjGqt LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OxKuwtPRArHE Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\OxKuwtPRArHE LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\PCdJYfSiqfVS Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\PCdJYfSiqfVS LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\PCdJYfSiqfVS LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\PEqybJZBKeux Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\PEqybJZBKeux LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\PGixKxTVEvLI Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\PGixKxTVEvLI LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\PGixKxTVEvLI LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\PYfOiompQhXU Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\PYfOiompQhXU LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\QbUdKrZWrOyb Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\QqfIzWynQadM Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\RKtMmmsrNIct Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\RKtMmmsrNIct LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\SskdWybClLWt Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\SskdWybClLWt LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\VIfYnFHEzWgj Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\VIfYnFHEzWgj LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\VJCeaijYsizA Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\VJCeaijYsizA LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\WdSlWkdGbYil LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\WdSlWkdGbYil Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\WdSlWkdGbYil LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\WdUexEvBRMgx Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\WdUexEvBRMgx LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\WfClIvPFHQkn Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\WfClIvPFHQkn LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\WipMzNFHJSmp Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\WmmorRTQlIsv Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\WmmorRTQlIsv LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\WmmorRTQlIsv LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XBWslSijGqtC Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XBWslSijGqtC LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XEegdBXZWfFC Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XEegdBXZWfFC LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XIpGiokshHEh Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XIpGiokshHEh LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XIpGiokshHEh LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XIrUbTVSnKux Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XItGvDAvKevY Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XItGvDAvKevY LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XSnCxMijQarS Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XTHKdWybCtJG Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XTHKdWybCtJG LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XTLWxZPKbROr Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XTLWxZPKbROr LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XTLWxZPKbROr LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XTQizGcfGxNK Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XTQizGcfGxNK LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XUlLVGtPRAux Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XUlLVGtPRAux LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XUshKiqtUlBY Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\XUshKiqtUlBY LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\YguhZBRTCwmp Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\YguhZBRTCwmp LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\YhNOkqxTVEor Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\YhNOkqxTVEor LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\YhNOkqxTVEor LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\YuhHIvKaixNK Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\YuhHIvKaixNK LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\YuorEnLNKtTQ Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\YyfFFGctMgjQ LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\YyfFFGctMgjQ Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ZDPCcpXUpMwz Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ZDPCcpXUpMwz LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ZDPCcpXUpMwz LastChat
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ZUgyylOqfFQn Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ZUgyylOqfFQn LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ZVIpSuxYpFCf Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Contacts\ZVIpSuxYpFCf LastSeenOnline
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account1 Enabled 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account1 NeedsSSL 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account1 Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account1 Server pop.ntlworld.com
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account1 Login dalecaffull
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account1 Password
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account1 MailClient C:\Program Files\Outlook Express\MSIMN.EXE
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account1 Port 110
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account2 Enabled 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account2 NeedsSSL 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account2 Email
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account2 Server ugimap.ecs.soton.ac.uk
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account2 Login dc1005
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account2 Password
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account2 MailClient C:\Program Files\Outlook Express\MSIMN.EXE
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\MailAccou nts\Account2 Port 143
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status1 Name Gaming
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status1 NameTag Gaming
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status1 PersonalMessage Playing Games....
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status1 ResponderMessage Sorry, gaming! #I said I'm gaming! #Will get back to you soon...
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status1 Status 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status1 UseReset 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status1 ResetDelay 300
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status2 Name Sleeping
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status2 NameTag Sleeping
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status2 PersonalMessage Zzzzzzzzzzzz.......
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status2 ResponderMessage Shhh! I'm sleeping! #Will get back to you when I wake....
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status2 Status 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status2 UseReset 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\PersonalS tatus\Status2 ResetDelay 300
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText1 IsStandalone 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText1 MultiMsg 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText1 ShortcutKey 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText1 AutoReplace taht
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText1 Message that
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText1 ShortcutMsg
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText2 IsStandalone 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText2 MultiMsg 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText2 ShortcutKey 11
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText2 AutoReplace
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText2 Message lol
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText2 ShortcutMsg
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText3 IsStandalone 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText3 MultiMsg 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText3 ShortcutKey 15
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText3 AutoReplace
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText3 Message love you xxx
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText3 ShortcutMsg
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText4 IsStandalone 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText4 MultiMsg 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText4 ShortcutKey 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText4 AutoReplace teh
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText4 Message the
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences\QuickText s\QuickText4 ShortcutMsg
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences OldPlusChecked 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences ContactWatchTime
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences FirstStart 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences NotifyAutoUpdate 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences TabChatAuto 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences SoundsAutoPlay 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences LockEnableShortcut 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences PersoStatusDispOnAway 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences PersoStatusRepeatDelay 180
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences PopMailUpdateSystem 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences PopMailShowNotif 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences PopMailCheckDelay 30
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences LogPublicKey640
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences LogPrivateKey640
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences LogKeyLength 640
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences ChatLogEncrypt 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences QuickTextAddToToolbar 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences SoundsPanelUsePreview 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences SoundsFirstUse 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences EnablePreferencesLock 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences ContactListTranspLevel 100
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences AutoAcceptDefault 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences AutoAcceptReq 65535
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences ChatTranspLevel 100
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences FontOverrideDefault 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences EnablePreviousRecall 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences IncreaseEditSize 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences FontOverrideStyle
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences FontOverrideColor 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences ParseCommands 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences ImproveColorChooser 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences FormatPanelInOptions 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences EnableFormatShortcuts 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences FormatShortcutsIrc 1
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences EventViewerMaximised 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences EventViewerPos
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences EventViewerLastShow
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live\uncleramsay@hotmail.com\Preferences SoundRandomDefLang 7
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live LanguageFile Lng_Default.ini
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live MessengerStartTime
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live MessengerIsRTL 0
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live DefaultUser uncleramsay@hotmail.com
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live AutoUpdateTime
HKEY_CURRENT_USER\SOFTWARE\Patchou\Messenger Plus! Live AllowMultiClients 0
HKEY_CLASSES_ROOT\MsgPlus.SoundPack
HKEY_CLASSES_ROOT\MsgPlus.SoundPack\DefaultIcon C:\Program Files\Messenger Plus! Live\MPTools.exe,2
HKEY_CLASSES_ROOT\MsgPlus.SoundPack\shell\open\com mand "C:\Program Files\Messenger Plus! Live\MPTools.exe" /ImportSoundPack="%1"
HKEY_CLASSES_ROOT\MsgPlus.SoundPack Messenger Plus! Sound Pack
HKEY_CLASSES_ROOT\.ple
HKEY_CLASSES_ROOT\.ple MsgPlus.Encrypted
HKEY_CLASSES_ROOT\.plp
HKEY_CLASSES_ROOT\.plp MsgPlus.SoundPack


Anyplace Control Commercial Remote Control Tool more information...
Details: Anyplace Control is a network program that allows the user to monitor and control another computer.
Status: Deleted

Infected files detected
c:\program files\anyplace control\anyplace control.cnt
c:\program files\anyplace control\anyplace control.gid
c:\program files\anyplace control\anyplace control.hlp
c:\program files\anyplace control\apc-addressbook.ini
c:\program files\anyplace control\apc-admin.ini
c:\program files\anyplace control\apc_admin.deu
c:\program files\anyplace control\apc_admin.esn
c:\program files\anyplace control\apc_admin.exe
c:\program files\anyplace control\apc_admin.exe.manifest
c:\program files\anyplace control\apc_admin.fra
c:\program files\anyplace control\apc_admin.ita
c:\program files\anyplace control\apc_admin.nld
c:\program files\anyplace control\apc_admin.rus
c:\program files\anyplace control\apc_crypto.dll
c:\program files\anyplace control\file_id.diz
c:\program files\anyplace control\history.txt
c:\program files\anyplace control\install.log
c:\program files\anyplace control\install.sss
c:\program files\anyplace control\installerpath.txt
c:\program files\anyplace control\license.txt
c:\program files\anyplace control\readme.txt
c:\program files\anyplace control\regkey.txt
c:\program files\anyplace control\uninstall.exe
c:\program files\anyplace control\languages\apc_admin.deu.lng
c:\program files\anyplace control\languages\apc_admin.esn.lng
c:\program files\anyplace control\languages\apc_admin.fra.lng
c:\program files\anyplace control\languages\apc_admin.ita.lng
c:\program files\anyplace control\languages\apc_admin.nld.lng
c:\program files\anyplace control\languages\apc_admin.ntv.lng
c:\program files\anyplace control\languages\apc_admin.rus.lng
c:\documents and settings\all users\desktop\anyplace control.lnk

Infected registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} DisplayName Anyplace Control 3.2.1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} ModifyPath "C:\Program Files\Anyplace Control\Uninstall.exe" "C:\Program Files\Anyplace Control\install.log"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} UninstallString "C:\Program Files\Anyplace Control\Uninstall.exe" "C:\Program Files\Anyplace Control\install.log" -u
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} InstallLocation C:\Program Files\Anyplace Control
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} InstallSource C:\Documents and Settings\All Users\Documents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} InstallSourceFile C:\Documents and Settings\All Users\Documents\AnyplaceControlInstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} InstallDate 09/18/2006
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} DisplayIcon C:\Program Files\Anyplace Control\apc_Admin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} Publisher Anyplace Control Software
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} URLInfoAbout http://www.anyplace-control.com
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} DisplayVersion 3.2.1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} HelpLink support@anyplace-control.com
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} HelpTelephone support@anyplace-control.com
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} BuildTimeStamp 389715465123958
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} SilentSettings C:\Program Files\Anyplace Control\install.sss
HKEY_CURRENT_USER\Software\Anyplace Control
HKEY_CURRENT_USER\Software\Anyplace Control\APC-Admin Language ENU


I'm InTouch Commercial Remote Control Tool more information...
Details: I'm InTouch is a Remote Administration Tool. You can control your computer from anywhere.
Status: Deleted

Infected files detected
c:\windows\system32\capsrces.dll
c:\windows\system32\drivers\rdsdrv.sys
c:\windows\system32\mallocdll.dll
c:\windows\system32\rdsdrv.dll
C:\HijackThis\backups\backup-20051018-190134-613.dll

Infected registry entries detected
HKEY_CLASSES_ROOT\AppID\01FileSys.EXE
HKEY_CLASSES_ROOT\AppID\01FileSys.EXE AppID {68D825D5-084B-49F0-A295-535D8A7E8360}
HKEY_CLASSES_ROOT\AppID\OERemote.EXE
HKEY_CLASSES_ROOT\AppID\OERemote.EXE AppID {C96AE16C-A914-4C29-A38E-8A376B96A39D}
HKEY_CLASSES_ROOT\AppID\OtlexAB.EXE
HKEY_CLASSES_ROOT\AppID\OtlexAB.EXE AppID {3F386802-A6CF-11D5-B610-0001032722C5}
HKEY_CLASSES_ROOT\AppID\OutlookExe.EXE
HKEY_CLASSES_ROOT\AppID\OutlookExe.EXE AppID {AAF90340-5A33-46AA-BF45-4F266BB6F53D}
HKEY_CLASSES_ROOT\AppID\SvrUtl.EXE
HKEY_CLASSES_ROOT\AppID\SvrUtl.EXE AppID {9CA815BE-6EA4-4BCC-B9F2-2A0E68A2F69B}
HKEY_CLASSES_ROOT\CapSources.CaptureSource
HKEY_CLASSES_ROOT\CapSources.CaptureSource\CLSID {CC72C10D-695B-11D4-B42D-00A00CC1BAD2}
HKEY_CLASSES_ROOT\CapSources.CaptureSource\CurVer CapSources.CaptureSource.1
HKEY_CLASSES_ROOT\CapSources.CaptureSource CaptureSource Class
HKEY_CLASSES_ROOT\CapSources.CaptureSource.1
HKEY_CLASSES_ROOT\CapSources.CaptureSource.1\CLSID {CC72C10D-695B-11D4-B42D-00A00CC1BAD2}
HKEY_CLASSES_ROOT\CapSources.CaptureSource.1 CaptureSource Class
HKEY_CLASSES_ROOT\CLSID\{CC72C10D-695B-11D4-B42D-00A00CC1BAD2}
HKEY_CLASSES_ROOT\CLSID\{CC72C10D-695B-11D4-B42D-00A00CC1BAD2}\InprocServer32 C:\WINDOWS\SYSTEM32\CapSrces.dll
HKEY_CLASSES_ROOT\CLSID\{CC72C10D-695B-11D4-B42D-00A00CC1BAD2}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{CC72C10D-695B-11D4-B42D-00A00CC1BAD2}\ProgID CapSources.CaptureSource.1
HKEY_CLASSES_ROOT\CLSID\{CC72C10D-695B-11D4-B42D-00A00CC1BAD2}\TypeLib {CC72C100-695B-11D4-B42D-00A00CC1BAD2}
HKEY_CLASSES_ROOT\CLSID\{CC72C10D-695B-11D4-B42D-00A00CC1BAD2}\VersionIndependentProgID CapSources.CaptureSource
HKEY_CLASSES_ROOT\CLSID\{CC72C10D-695B-11D4-B42D-00A00CC1BAD2} CaptureSource Class
HKEY_CLASSES_ROOT\Interface\{CC72C10C-695B-11D4-B42D-00A00CC1BAD2}
HKEY_CLASSES_ROOT\Interface\{CC72C10C-695B-11D4-B42D-00A00CC1BAD2}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{CC72C10C-695B-11D4-B42D-00A00CC1BAD2}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{CC72C10C-695B-11D4-B42D-00A00CC1BAD2}\TypeLib {CC72C100-695B-11D4-B42D-00A00CC1BAD2}
HKEY_CLASSES_ROOT\Interface\{CC72C10C-695B-11D4-B42D-00A00CC1BAD2}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{CC72C10C-695B-11D4-B42D-00A00CC1BAD2} ICaptureSource
HKEY_CLASSES_ROOT\TypeLib\{CC72C100-695B-11D4-B42D-00A00CC1BAD2}
HKEY_CLASSES_ROOT\TypeLib\{CC72C100-695B-11D4-B42D-00A00CC1BAD2}\1.0\0\win32 C:\WINDOWS\SYSTEM32\CapSrces.dll
HKEY_CLASSES_ROOT\TypeLib\{CC72C100-695B-11D4-B42D-00A00CC1BAD2}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{CC72C100-695B-11D4-B42D-00A00CC1BAD2}\1.0\HELPDIR C:\WINDOWS\SYSTEM32\
HKEY_CLASSES_ROOT\TypeLib\{CC72C100-695B-11D4-B42D-00A00CC1BAD2}\1.0 CapSources 1.0 Type Library
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/iitloader.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/iitloader.dll .Owner {81F0C919-AB0B-4F5C-932D-5CEEF05879E9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/iitloader.dll {81F0C919-AB0B-4F5C-932D-5CEEF05879E9}


MyWebEx PC Commercial Remote Control Tool more information...
Details: MyWebEx PC gives you the ability to access your PC remotely anywhere and anytime.
Status: Deleted

Infected files detected
c:\windows\downloaded program files\mwcliun.exe


Remotely Anywhere Server Edition Commercial Remote Control Tool more information...
Details: Remotely Anywhere Server Edtion is remote admininstration tool that allows a server to be remotely monitored and managed.
Status: Deleted

Infected files detected
c:\windows\downloaded program files\ractrl.dll
c:\windows\downloaded program files\ractrl.inf
c:\windows\system32\ractrlkeyhook.dll
C:\Program Files\LogMeIn\update\2-30-523.bak\ra16app.exe
C:/WINDOWS/Downloaded Program Files/RACtrl.dll
C:/WINDOWS/System32/ractrlkeyhook.dll

Infected registry entries detected
HKEY_CLASSES_ROOT\AppID\{F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\AppID\{F9130221-AE49-4EFA-92F0-105E97F63216} RACtrl
HKEY_CLASSES_ROOT\AppID\RACtrl.DLL
HKEY_CLASSES_ROOT\AppID\RACtrl.DLL AppID {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\CLSID\{03D19749-C5FA-4CCC-99AB-00AB2AF45ACD}
HKEY_CLASSES_ROOT\CLSID\{03D19749-C5FA-4CCC-99AB-00AB2AF45ACD}\InprocServer32 C:\WINDOWS\Downloaded Program Files\RACtrl.dll
HKEY_CLASSES_ROOT\CLSID\{03D19749-C5FA-4CCC-99AB-00AB2AF45ACD}\InprocServer32 ThreadingModel apartment
HKEY_CLASSES_ROOT\CLSID\{03D19749-C5FA-4CCC-99AB-00AB2AF45ACD}\MiscStatus\1 131473
HKEY_CLASSES_ROOT\CLSID\{03D19749-C5FA-4CCC-99AB-00AB2AF45ACD}\MiscStatus 0
HKEY_CLASSES_ROOT\CLSID\{03D19749-C5FA-4CCC-99AB-00AB2AF45ACD}\ProgID RACtrl.FileXferCtrl.1
HKEY_CLASSES_ROOT\CLSID\{03D19749-C5FA-4CCC-99AB-00AB2AF45ACD}\ToolboxBitmap32 C:\WINDOWS\Downloaded Program Files\RACtrl.dll, 1
HKEY_CLASSES_ROOT\CLSID\{03D19749-C5FA-4CCC-99AB-00AB2AF45ACD}\TypeLib {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\CLSID\{03D19749-C5FA-4CCC-99AB-00AB2AF45ACD}\Version 1.0
HKEY_CLASSES_ROOT\CLSID\{03D19749-C5FA-4CCC-99AB-00AB2AF45ACD}\VersionIndependentProgID RACtrl.FileXferCtrl
HKEY_CLASSES_ROOT\CLSID\{03D19749-C5FA-4CCC-99AB-00AB2AF45ACD} File Transfer ActiveX Client
HKEY_CLASSES_ROOT\CLSID\{03D19749-C5FA-4CCC-99AB-00AB2AF45ACD} AppID {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\CLSID\{556EEC63-31E2-47C3-BF29-DFF799D2FE04}
HKEY_CLASSES_ROOT\CLSID\{556EEC63-31E2-47C3-BF29-DFF799D2FE04}\InprocServer32 C:\WINDOWS\Downloaded Program Files\RACtrl.dll
HKEY_CLASSES_ROOT\CLSID\{556EEC63-31E2-47C3-BF29-DFF799D2FE04}\InprocServer32 ThreadingModel apartment
HKEY_CLASSES_ROOT\CLSID\{556EEC63-31E2-47C3-BF29-DFF799D2FE04}\MiscStatus\1 131473
HKEY_CLASSES_ROOT\CLSID\{556EEC63-31E2-47C3-BF29-DFF799D2FE04}\MiscStatus 0
HKEY_CLASSES_ROOT\CLSID\{556EEC63-31E2-47C3-BF29-DFF799D2FE04}\ProgID RACtrl.rcxcontrol.1
HKEY_CLASSES_ROOT\CLSID\{556EEC63-31E2-47C3-BF29-DFF799D2FE04}\ToolboxBitmap32 C:\WINDOWS\Downloaded Program Files\RACtrl.dll, 1
HKEY_CLASSES_ROOT\CLSID\{556EEC63-31E2-47C3-BF29-DFF799D2FE04}\TypeLib {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\CLSID\{556EEC63-31E2-47C3-BF29-DFF799D2FE04}\Version 1.0
HKEY_CLASSES_ROOT\CLSID\{556EEC63-31E2-47C3-BF29-DFF799D2FE04}\VersionIndependentProgID RACtrl.rcxcontrol
HKEY_CLASSES_ROOT\CLSID\{556EEC63-31E2-47C3-BF29-DFF799D2FE04} Remote Access ActiveX Client
HKEY_CLASSES_ROOT\CLSID\{556EEC63-31E2-47C3-BF29-DFF799D2FE04} AppID {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\CLSID\{FA5369ED-D19A-434C-8F59-EE90D690D36C}
HKEY_CLASSES_ROOT\CLSID\{FA5369ED-D19A-434C-8F59-EE90D690D36C}\InprocServer32 C:\WINDOWS\Downloaded Program Files\RACtrl.dll
HKEY_CLASSES_ROOT\CLSID\{FA5369ED-D19A-434C-8F59-EE90D690D36C}\InprocServer32 ThreadingModel apartment
HKEY_CLASSES_ROOT\CLSID\{FA5369ED-D19A-434C-8F59-EE90D690D36C}\MiscStatus\1 131473
HKEY_CLASSES_ROOT\CLSID\{FA5369ED-D19A-434C-8F59-EE90D690D36C}\MiscStatus 0
HKEY_CLASSES_ROOT\CLSID\{FA5369ED-D19A-434C-8F59-EE90D690D36C}\ProgID RACtrl.ChatCtrl.1
HKEY_CLASSES_ROOT\CLSID\{FA5369ED-D19A-434C-8F59-EE90D690D36C}\ToolboxBitmap32 C:\WINDOWS\Downloaded Program Files\RACtrl.dll, 1
HKEY_CLASSES_ROOT\CLSID\{FA5369ED-D19A-434C-8F59-EE90D690D36C}\TypeLib {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\CLSID\{FA5369ED-D19A-434C-8F59-EE90D690D36C}\Version 1.0
HKEY_CLASSES_ROOT\CLSID\{FA5369ED-D19A-434C-8F59-EE90D690D36C}\VersionIndependentProgID RACtrl.ChatCtrl
HKEY_CLASSES_ROOT\CLSID\{FA5369ED-D19A-434C-8F59-EE90D690D36C} Chat Activex Control
HKEY_CLASSES_ROOT\CLSID\{FA5369ED-D19A-434C-8F59-EE90D690D36C} AppID {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\CLSID\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
HKEY_CLASSES_ROOT\CLSID\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\InprocServer32 C:\WINDOWS\Downloaded Program Files\RACtrl.dll
HKEY_CLASSES_ROOT\CLSID\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\InprocServer32 ThreadingModel apartment
HKEY_CLASSES_ROOT\CLSID\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\MiscStatus\1 131473
HKEY_CLASSES_ROOT\CLSID\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\MiscStatus 0
HKEY_CLASSES_ROOT\CLSID\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\ProgID RACtrl.PerfViewCtrl.1
HKEY_CLASSES_ROOT\CLSID\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\ToolboxBitmap32 C:\WINDOWS\Downloaded Program Files\RACtrl.dll, 1
HKEY_CLASSES_ROOT\CLSID\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\TypeLib {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\CLSID\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\Version 1.0
HKEY_CLASSES_ROOT\CLSID\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\VersionIndependentProgID RACtrl.PerfViewCtrl
HKEY_CLASSES_ROOT\CLSID\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} Performance Viewer Activex Control
HKEY_CLASSES_ROOT\CLSID\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} AppID {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\Interface\{6A01FDD3-650D-4790-8B25-0EADECC45D34}
HKEY_CLASSES_ROOT\Interface\{6A01FDD3-650D-4790-8B25-0EADECC45D34}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{6A01FDD3-650D-4790-8B25-0EADECC45D34}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{6A01FDD3-650D-4790-8B25-0EADECC45D34}\TypeLib {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\Interface\{6A01FDD3-650D-4790-8B25-0EADECC45D34}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{6A01FDD3-650D-4790-8B25-0EADECC45D34} IChatCtrl
HKEY_CLASSES_ROOT\Interface\{82B2FDFA-440A-4081-9C68-49E50E52A447}
HKEY_CLASSES_ROOT\Interface\{82B2FDFA-440A-4081-9C68-49E50E52A447}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{82B2FDFA-440A-4081-9C68-49E50E52A447}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{82B2FDFA-440A-4081-9C68-49E50E52A447}\TypeLib {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\Interface\{82B2FDFA-440A-4081-9C68-49E50E52A447}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{82B2FDFA-440A-4081-9C68-49E50E52A447} IFileXferCtrl
HKEY_CLASSES_ROOT\Interface\{D2E1AC54-529F-4D76-BBDF-FEC5312D163C}
HKEY_CLASSES_ROOT\Interface\{D2E1AC54-529F-4D76-BBDF-FEC5312D163C}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{D2E1AC54-529F-4D76-BBDF-FEC5312D163C}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{D2E1AC54-529F-4D76-BBDF-FEC5312D163C}\TypeLib {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\Interface\{D2E1AC54-529F-4D76-BBDF-FEC5312D163C}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{D2E1AC54-529F-4D76-BBDF-FEC5312D163C} IPerfViewCtrl
HKEY_CLASSES_ROOT\Interface\{D3BF682F-0975-45A8-BC32-3531732EA111}
HKEY_CLASSES_ROOT\Interface\{D3BF682F-0975-45A8-BC32-3531732EA111}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{D3BF682F-0975-45A8-BC32-3531732EA111}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{D3BF682F-0975-45A8-BC32-3531732EA111}\TypeLib {F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\Interface\{D3BF682F-0975-45A8-BC32-3531732EA111}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{D3BF682F-0975-45A8-BC32-3531732EA111} Ircxcontrol
HKEY_CLASSES_ROOT\RACtrl.ChatCtrl.1
HKEY_CLASSES_ROOT\RACtrl.ChatCtrl.1\CLSID {FA5369ED-D19A-434C-8F59-EE90D690D36C}
HKEY_CLASSES_ROOT\RACtrl.ChatCtrl.1 Chat Activex Control
HKEY_CLASSES_ROOT\RACtrl.ChatCtrl
HKEY_CLASSES_ROOT\RACtrl.ChatCtrl\CLSID {FA5369ED-D19A-434C-8F59-EE90D690D36C}
HKEY_CLASSES_ROOT\RACtrl.ChatCtrl\CurVer RACtrl.ChatCtrl.1
HKEY_CLASSES_ROOT\RACtrl.ChatCtrl Chat Activex Control
HKEY_CLASSES_ROOT\RACtrl.FileXferCtrl.1
HKEY_CLASSES_ROOT\RACtrl.FileXferCtrl.1\CLSID {03D19749-C5FA-4CCC-99AB-00AB2AF45ACD}
HKEY_CLASSES_ROOT\RACtrl.FileXferCtrl.1 File Transfer ActiveX Client
HKEY_CLASSES_ROOT\RACtrl.FileXferCtrl
HKEY_CLASSES_ROOT\RACtrl.FileXferCtrl\CLSID {03D19749-C5FA-4CCC-99AB-00AB2AF45ACD}
HKEY_CLASSES_ROOT\RACtrl.FileXferCtrl\CurVer RACtrl.FileXferCtrl.1
HKEY_CLASSES_ROOT\RACtrl.FileXferCtrl File Transfer ActiveX Client
HKEY_CLASSES_ROOT\RACtrl.PerfViewCtrl.1
HKEY_CLASSES_ROOT\RACtrl.PerfViewCtrl.1\CLSID {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
HKEY_CLASSES_ROOT\RACtrl.PerfViewCtrl.1 Performance Viewer Activex Control
HKEY_CLASSES_ROOT\RACtrl.PerfViewCtrl
HKEY_CLASSES_ROOT\RACtrl.PerfViewCtrl\CLSID {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
HKEY_CLASSES_ROOT\RACtrl.PerfViewCtrl\CurVer RACtrl.PerfViewCtrl.1
HKEY_CLASSES_ROOT\RACtrl.PerfViewCtrl Performance Viewer Activex Control
HKEY_CLASSES_ROOT\RACtrl.rcxcontrol.1
HKEY_CLASSES_ROOT\RACtrl.rcxcontrol.1\CLSID {556EEC63-31E2-47C3-BF29-DFF799D2FE04}
HKEY_CLASSES_ROOT\RACtrl.rcxcontrol.1 Remote Access ActiveX Client
HKEY_CLASSES_ROOT\RACtrl.rcxcontrol
HKEY_CLASSES_ROOT\RACtrl.rcxcontrol\CLSID {556EEC63-31E2-47C3-BF29-DFF799D2FE04}
HKEY_CLASSES_ROOT\RACtrl.rcxcontrol\CurVer RACtrl.rcxcontrol.1
HKEY_CLASSES_ROOT\RACtrl.rcxcontrol Remote Access ActiveX Client
HKEY_CLASSES_ROOT\TypeLib\{F9130221-AE49-4EFA-92F0-105E97F63216}
HKEY_CLASSES_ROOT\TypeLib\{F9130221-AE49-4EFA-92F0-105E97F63216}\1.0\0\win32 C:\WINDOWS\Downloaded Program Files\RACtrl.dll
HKEY_CLASSES_ROOT\TypeLib\{F9130221-AE49-4EFA-92F0-105E97F63216}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{F9130221-AE49-4EFA-92F0-105E97F63216}\1.0\HELPDIR C:\WINDOWS\Downloaded Program Files\
HKEY_CLASSES_ROOT\TypeLib\{F9130221-AE49-4EFA-92F0-105E97F63216}\1.0 RemotelyAnywhere
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\Contains\Files C:\WINDOWS\system32\unicows.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\Contains\Files C:\WINDOWS\system32\ractrlkeyhook.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\Contains\Files C:\WINDOWS\Downloaded Program Files\RACtrl.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\DownloadInformation CODEBASE https://secure.logmein.com/activex/ractrl.cab?lmi=100
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\DownloadInformation INF C:\WINDOWS\Downloaded Program Files\RACtrl.inf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\InstalledVersion 1,0,0,242
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}\InstalledVersion LastModified Mon, 14 Aug 2006 09:44:40 GMT
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} SystemComponent 0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} Installer MSICD
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/RACtrl.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/RACtrl.dll .Owner {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ModuleUsage\C:/WINDOWS/Downloaded Program Files/RACtrl.dll {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\SharedDLLS C:\WINDOWS\Downloaded Program Files\RACtrl.dll 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ModuleUsage\C:/WINDOWS/System32/ractrlkeyhook.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ModuleUsage\C:/WINDOWS/System32/ractrlkeyhook.dll .Owner {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ModuleUsage\C:/WINDOWS/System32/ractrlkeyhook.dll {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}


Ultr@VNC Commercial Remote Control Tool more information...
Details: Ultr@VNC is a client/server software that allows user to remotely control a computer over any TCP/IP connection as if you were in front of it.
Status: Deleted

Infected files detected
c:\windows\system32\'


Zango.SearchAssistant Adware (General) more information...
Details: Zango Search Assistant opens new browser windows showing websites based on the previous websites you visit.
Status: Deleted

Infected files detected
c:\program files\mozilla firefox\plugins\npclntax.dll


TrustIn.Search Adware (General) more information...
Status: Deleted

Infected files detected
c:\windows\system32\tisa.cnf


NewDotNet Browser Plug-in more information...
Details: New.Net is an Internet Explorer spyware/hijacker plug-in that adds subdomains of 'new.net' to your name resolution system (Windows Host file), resulting in what appear to be extra top-level domains (.shop, and so on) being resolvable.
Status: Deleted

Infected files detected
C:\WINDOWS\SYSTEM32\DLLCACHE\wmm2ae.dll


Zango.Fireworks_Extravaganza Adware Installer more information...
Status: Deleted

Infected files detected
C:\WINDOWS\SYSTEM32\FHMcom_OxleyStrip dir\expire.scf


KaZaA P2P Program more information...
Details: KaZaA is a peer-to-peer (P2P) application that allows its users to join together in a network via the Internet and share files from each other's hard drives.
Status: Deleted

Infected registry entries detected
HKEY_CURRENT_USER\Software\Kazaa
HKEY_CURRENT_USER\Software\Kazaa\Advanced Status Installed
HKEY_CURRENT_USER\Software\Kazaa\Settings +
HKEY_CURRENT_USER\Software\Kazaa\Settings Date
HKEY_CURRENT_USER\Software\Kazaa\Settings UseCount 0
HKEY_CURRENT_USER\Software\Kazaa\Transfer +
HKEY_CURRENT_USER\Software\Kazaa\Transfer NoUploadLimitWhenIdle 1
HKEY_CURRENT_USER\Software\Kazaa Tmp 0


Access Remote PC Commercial Remote Control Tool more information...
Details: This program lets user access your PC from another PC over any Internet, LAN or phone connection.
Status: Deleted

Infected registry entries detected
HKEY_CURRENT_USER\Software\Access Remote PC
HKEY_CURRENT_USER\Software\Access Remote PC\Client\Options nWndHeight 530
HKEY_CURRENT_USER\Software\Access Remote PC\Client\Options nWndWidth 768
HKEY_CURRENT_USER\Software\Access Remote PC\Client\Options bHideConnectBar 1
HKEY_CURRENT_USER\Software\Access Remote PC\Client\Options bHideStatusBar 0
HKEY_CURRENT_USER\Software\Access Remote PC\Client\Options bHideToolBar 0
HKEY_CURRENT_USER\Software\Access Remote PC\Client\RecentConnectionList\Connection1 192.168.2.39
HKEY_CURRENT_USER\Software\Access Remote PC\Client\RecentConnectionList\Connection2 80.7.178.38
HKEY_CLASSES_ROOT\CLSID\{210A1F7D-32D7-1366-2EED-A979E62F93A9}
HKEY_CLASSES_ROOT\CLSID\{210A1F7D-32D7-1366-2EED-A979E62F93A9}\ProgID PDWizard.Package
HKEY_CLASSES_ROOT\CLSID\{210A1F7D-32D7-1366-2EED-A979E62F93A9}\TypeLib {0DDF3B5A-E692-11D1-AB06-00AA00BDD685}
HKEY_CLASSES_ROOT\CLSID\{210A1F7D-32D7-1366-2EED-A979E62F93A9}\VERSION 2.0
HKEY_CLASSES_ROOT\CLSID\{210A1F7D-32D7-1366-2EED-A979E62F93A9} PDWizard.Package
HKEY_CLASSES_ROOT\CLSID\{210A1F7D-32D7-1366-2EED-A979E62F93A9} uctVfakLWfSZ MQvFRAS~yzDq@OqJxSMW~[aa^yJ|ClHcAhODOYacvKxvuD`QeBVGrAJ[PtJ~crMOzBEfbTBN@@K~vWx|jflTGgJ{oflr\S`iyAgu_wBIe iAnt~}|GixRMKM
HKEY_CURRENT_USER\Software\Access Remote PC\Client
HKEY_CURRENT_USER\Software\Access Remote PC\Client\Options nWndHeight 530
HKEY_CURRENT_USER\Software\Access Remote PC\Client\Options nWndWidth 768
HKEY_CURRENT_USER\Software\Access Remote PC\Client\Options bHideConnectBar 1
HKEY_CURRENT_USER\Software\Access Remote PC\Client\Options bHideStatusBar 0
HKEY_CURRENT_USER\Software\Access Remote PC\Client\Options bHideToolBar 0
HKEY_CURRENT_USER\Software\Access Remote PC\Client\RecentConnectionList\Connection1 192.168.2.39
HKEY_CURRENT_USER\Software\Access Remote PC\Client\RecentConnectionList\Connection2 80.7.178.38


VNC Enterprise Edition Commercial Remote Control Tool more information...
Details: VNC stands for Virtual Network Computing. It is remote control software which allows you to view and interact with one computer (the "server") using a simple program (the "viewer") on another computer anywhere on the Internet. The two computers don't
Status: Deleted

Infected registry entries detected
HKEY_CURRENT_USER\Software\RealVNC


Y! Jacked Password Cracker/Stealer more information...
Details: Yahoo! Messenger password sender.
Status: Deleted

Infected registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E666}


Need2FindBar Potentially Unwanted Program more information...
Details: Need2FindBar is a browser helper object (BHO) toolbar that has a search function.
Status: Deleted

Infected registry entries detected
HKEY_CLASSES_ROOT\MSIEDe1egate.Application.2
HKEY_CLASSES_ROOT\MSIEDe1egate.Application.2\CLSID {0002DF01-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\MSIEDe1egate.Application.2 Internet Exp1orer (Ver 1.56399)


Remote Desktop Control Commercial Remote Control Tool more information...
Details: Remote Desktop Control allows the user to remotely control any computer, running under the Microsoft Windows system in a TCP/IP network or the Internet. The user can see a remote desktop on his or her own screen and use the mouse and keyboard to control t
Status: Deleted

Infected registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} DisplayName Anyplace Control 3.2.1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} ModifyPath "C:\Program Files\Anyplace Control\Uninstall.exe" "C:\Program Files\Anyplace Control\install.log"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} UninstallString "C:\Program Files\Anyplace Control\Uninstall.exe" "C:\Program Files\Anyplace Control\install.log" -u
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} InstallLocation C:\Program Files\Anyplace Control
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} InstallSource C:\Documents and Settings\All Users\Documents
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} InstallSourceFile C:\Documents and Settings\All Users\Documents\AnyplaceControlInstall.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} InstallDate 09/18/2006
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} DisplayIcon C:\Program Files\Anyplace Control\apc_Admin.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} Publisher Anyplace Control Software
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} URLInfoAbout http://www.anyplace-control.com
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} DisplayVersion 3.2.1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} HelpLink support@anyplace-control.com
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} HelpTelephone support@anyplace-control.com
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} BuildTimeStamp 389715465123958
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\{51FF0A13-A703-4B5E-8927-A3146EE525FE} SilentSettings C:\Program Files\Anyplace Control\install.sss


My Spy RAT more information...
Details: My Spy is a Remote Administration Tool, that when run, provides an attacker with the capability of remotely controlling a machine.
Status: Deleted

Infected registry entries detected
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Active Setup\Installed Components\{Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E666}


Accoona.Toolbar Toolbar more information...
Details: The Accoona Toolbar is a Internet Explorer toolbar that is bundled and installed with other programs.
Status: Deleted

Infected registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\Wise Solutions\Wise Installation System\Repair\C:/Program Files/Accoona/INSTALL1.LOG
HKEY_LOCAL_MACHINE\SOFTWARE\Wise Solutions\Wise Installation System\Repair\C:/Program Files/Accoona/INSTALL1.LOG 1\Software\Microsoft\Internet Explorer\Main\\Use Search Asst
HKEY_LOCAL_MACHINE\SOFTWARE\Wise Solutions\Wise Installation System\Repair\C:/Program Files/Accoona/INSTALL1.LOG 2\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant
HKEY_LOCAL_MACHINE\SOFTWARE\Wise Solutions\Wise Installation System\Repair\C:/Program Files/Accoona/INSTALL1.LOG 1\Software\Microsoft\Internet Explorer\Main\\Use Custom Search URL
HKEY_LOCAL_MACHINE\SOFTWARE\Wise Solutions\Wise Installation System\Repair\C:/Program Files/Accoona/INSTALL1.LOG 2\SOFTWARE\Accoona\Toolbar\\Web Search URL
HKEY_LOCAL_MACHINE\SOFTWARE\Wise Solutions\Wise Installation System\Repair\C:/Program Files/Accoona/INSTALL1.LOG 2\SOFTWARE\Accoona\Toolbar\\Business Profile On
HKEY_LOCAL_MACHINE\SOFTWARE\Wise Solutions\Wise Installation System\Repair\C:/Program Files/Accoona/INSTALL1.LOG 2\SOFTWARE\Accoona\Toolbar\\Cache Size


Mass PW Steal Password Cracker/Stealer more information...
Details: Mass Pw steal is a program designed for stealing passwords from many computers at once. It will extract passwords from IE autocomplete, Outlook and IE password protected sites.
Status: Deleted

Infected registry entries detected
HKEY_CURRENT_USER\Software\NirSoft\MessenPass
HKEY_CURRENT_USER\Software\NirSoft\MessenPass ShowGridLines 0
HKEY_CURRENT_USER\Software\NirSoft\MessenPass SaveFilterIndex 0
HKEY_CURRENT_USER\Software\NirSoft\MessenPass WinPos
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Columns
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Sort 0


GunnSpy v0.52 Backdoor more information...
Details: GunnSpy is a Backdoor Trojan that steals the user information and mail it to a pre-defined e-mail address.
Status: Deleted

Infected registry entries detected
HKEY_CURRENT_USER\Software\NirSoft\MessenPass
HKEY_CURRENT_USER\Software\NirSoft\MessenPass ShowGridLines 0
HKEY_CURRENT_USER\Software\NirSoft\MessenPass SaveFilterIndex 0
HKEY_CURRENT_USER\Software\NirSoft\MessenPass WinPos
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Columns
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Sort 0


PMG Connect Commercial Remote Control Tool more information...
Details: It's a remote Control tool,which connects directly on to the target PC without the victim's consent.
Status: Deleted

Infected registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\Possemeeg
HKEY_LOCAL_MACHINE\SOFTWARE\Possemeeg\PMG Connect\SC ThisMachineUUID 33B1860E-C448-47E2-BEE6-95FC6AA9FE75
HKEY_LOCAL_MACHINE\SOFTWARE\Possemeeg\PMG Connect ServerFlags 8
HKEY_LOCAL_MACHINE\SOFTWARE\Possemeeg\PMG Connect UserFlags 0
HKEY_LOCAL_MACHINE\SOFTWARE\Possemeeg\PMG Connect UserName dale


RePass Password Cracker/Stealer more information...
Details: Repass is a hidden trojan which run's on the vicitm's machine without his/her consent.
Status: Deleted

Infected registry entries detected
HKEY_CURRENT_USER\Software\NirSoft\MessenPass
HKEY_CURRENT_USER\Software\NirSoft\MessenPass ShowGridLines 0
HKEY_CURRENT_USER\Software\NirSoft\MessenPass SaveFilterIndex 0
HKEY_CURRENT_USER\Software\NirSoft\MessenPass WinPos
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Columns
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Sort 0


I-Spy (the_seed) Password Cracker/Stealer more information...
Details: I-Spy is a kind of spyware that capture passwords of Dialup, cached, mail, network and mozilla in a text file and upload that file automatically to the pre-defined web address.
Status: Deleted

Infected registry entries detected
HKEY_CURRENT_USER\Software\NirSoft\MessenPass
HKEY_CURRENT_USER\Software\NirSoft\MessenPass ShowGridLines 0
HKEY_CURRENT_USER\Software\NirSoft\MessenPass SaveFilterIndex 0
HKEY_CURRENT_USER\Software\NirSoft\MessenPass WinPos
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Columns
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Sort 0


Cookie: a.websponsors Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@a.websponsors[2].txt


Cookie: ad.yieldmanager Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@ad.yieldmanager[1].txt
c:\documents and settings\dale\cookies\dale@ad.yieldmanager[3].txt


Cookie: adrevolver Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@adrevolver[2].txt


Cookie: Advertising.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@advertising[1].txt


Cookie: PriceBandit Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@apmebf[1].txt


Cookie: ATDMT.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@atdmt[2].txt


Cookie: casalemedia.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@casalemedia[2].txt


Cookie: Cdfreaks Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@cdfreaks[2].txt


Cookie: FastClick.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@fastclick[2].txt


Cookie: GeoCities Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@geocities[2].txt


Cookie: GoToMyPC.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@gotomypc[2].txt


Cookie: Hitbox.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@hitbox[2].txt


Cookie: IndexTools.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@indextools[2].txt


Cookie: Mediaplex.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@mediaplex[1].txt


Cookie: PriceGrabber Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@pricegrabber[1].txt


Cookie: QuestionMarket.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@questionmarket[2].txt


Cookie: SageAnalyst Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@sageanalyst[1].txt
c:\documents and settings\dale\cookies\dale@sageanalyst[2].txt


Cookie: BS.Serving-Sys Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@serving-sys[1].txt


Cookie: statcounter.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@statcounter[1].txt


Cookie: TribalFusion.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@tribalfusion[1].txt


Cookie: IEMenuExtension Toolbar Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@www.effectivebrand[1].txt


Cookie: RegNow Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@www.regnow[2].txt


Cookie: Ajan 1.0 Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted

Infected cookies detected
c:\documents and settings\dale\cookies\dale@xiti[1].txt


Thanks for the help...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 02-10-2006, 01:52 AM
Neal's Avatar
Senior Member
 
Join Date: Sep 2005
Posts: 5,524
Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!
Re: Computer Problems....

WOW, I don't know where to start, except to say I would never trust this computer again. It appears to of been seriously compromised. If you have ever done any online banking, credit card transactions etc. you should notify those companies that you have had some serious hacks on your computer. More than likely all passwords have been stolen.


We can never be sure if everyhting was removed as things are so deeply hidden even from counterspy which is a very agressive scanner/remover.


We can keep going if you want your call.


Is your computer behaving better now?


Try running counterspy again and see what it finds and we can see if some of that stuff comes back from hidden files that can't be removed.


Good luck.
__________________
Stalking and killing Spyware

Have we helped you? Please consider a donation to help keep D-A-L free. Click on donate below



MALWARE: READ FIRST Procedures:
|_ SpyBot V1.5 _|_ HijackThis Log __V2.0.2 _|




ASAP: promoting a high standard and quality of security support no matter where you seek help.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 02-10-2006, 02:02 PM
Junior Member
New Recruit
 
Join Date: Nov 2005
Posts: 38
uncleramsay Is a beginner here at D-A-L
Re: Computer Problems....

Which item in particular was it that you were concerned about?
Most of the things that CounterSpy picked up were things I already knew about.
The MessengerPlus! software, and ALL the remote controlling software was installed by me, and I am confident that it was all secure.
However, I cannot deny that the 'Password Hacker' programs shocked me a bit, as my computer is behind two firewalls, an antivirus, and spyware resident shield.

Anyway, I have checked all my accounts, and nothing has been compromised in any way. No transactions have been made, and no e-mails have been read etc...
I have changed all my passwords anyway as a precaution, and notified my bank.

Most of the symptoms are now solved, except the problem with my CD Drive (which is the most annoying one!) any ideas on this problem?

Is my computer now secure? I reran CounterSpy, and all the other scanners you recommended, and they all came out clean.

Thanks a lot for your help...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 02-10-2006, 11:24 PM
Neal's Avatar
Senior Member
 
Join Date: Sep 2005
Posts: 5,524
Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!Neal is a D-A-L Rockstar!
Re: Computer Problems....

That was one of them, that cracker also there was a backdoor trojan, list is to long to go back thru it all but if you feel confident all is ok.


Try xphelp section for the CD thing and see if they can help you on that.


Good luck.
__________________
Stalking and killing Spyware

Have we helped you? Please consider a donation to help keep D-A-L free. Click on donate below



MALWARE: READ FIRST Procedures:
|_ SpyBot V1.5 _|_ HijackThis Log __V2.0.2 _|




ASAP: promoting a high standard and quality of security support no matter where you seek help.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
help me with my computer problems plz CelestePulchra Spyware, Adware, Viruses and HijackThis Logs 3 25-05-2008 02:03 PM
Computer problems Xboxboy Spyware, Adware, Viruses and HijackThis Logs 1 29-04-2008 12:25 PM
Computer Problems compduder122 Windows XP Help 1 28-01-2007 02:10 AM
Computer Problems MattCo Windows XP Help 1 15-07-2006 12:45 AM
new computer problems. Tekster General Hardware Issues 1 09-10-2005 03:33 AM


All times are GMT +1. The time now is 11:16 AM.

Bottom Corner