Dialer.Adultchat

Printer Friendly Page

Updated: February 13, 2007 11:35:28 AM
Type: Dialer
Risk Impact: Low
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP


When Dialer.AdultChat is executed, it performs the following actions:
  1. May display a message about its content, allowing a user to cancel or continue. If the user selects to continue, the dialer opens a Web page that displays terms and conditions. The page states the destination of the call, its charges, and content, as well as gives the user the option to cancel or continue.

  2. May drop shortcuts in the following locations:

    • %UserProfile%\Desktop
    • %UserProfile%\Start Menu
    • %UserProfile%\Start Menu\Programs
    • %SystemDrive%\Document and Settings\All Users\Desktop|

      Note:
    • %UserProfile% is a variable that refers to the current user's profile folder. By default, this is C:\Documents and Settings\[CURRENT USER] (Windows NT/2000/XP).
    • %SystemDrive% is a variable that refers to the drive on which Windows is installed. By default, this is drive C.

  3. May creates one or more of the following files:

    • %Windir%\Downloaded Program Files\games.inf
    • %Windir%\LastGood\Downloaded Program Files\games.inf
    • %System%\EasyDates_sg-uninstall.exe
    • %System%\HotAction_sg-uninstall.exe
    • %ProgramFiles%\pinfo\dialers\lisa\lisa.exe
    • %ProgramFiles%\nog\dialers\lisa\lisa.exe
    • %ProgramFiles%\hbt\dialers\blondes\blondes.exe
    • %ProgramFiles%\hbt\dialers\virgins_ie\[FILENAME].exe
    • %ProgramFiles%\scom\dialers\gay_sexy\[FILENAME].exe
    • %ProgramFiles%\scom\dialers\gay_sexy_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\hbt\dialers\hot_tarts_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\hbt\dialers\blonde_tarts_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\mpb\dialers\hot_tarts_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\playboy\dialers\playboy\[FILENAME].exe
    • %ProgramFiles%\playboy\dialers\playboy_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\sbl\dialers\sexy_blondes\[FILENAME].exe
    • %ProgramFiles%\sym\dialers\sexy_blondes_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\zlg\Dialers\Sizzling_Blondes_au\Sizzling_Blondes_au.exe
    • %ProgramFiles%\xau\xau\xau.exe
    • %System%\sndplay.dll
    • %ProgramFiles%\video1\dialers\hot_tarts_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\fbb\freebbaccess\freebbaccess.exe
    • %ProgramFiles%\FreeBBAccess.lnk
    • %ProgramFiles%\infxp\infxp\infxp.exe
    • %ProgramFiles%\comsoft\dialers\easydates\[FILENAME].exe
    • %ProgramFiles%\comsoft\dialers\easydates_sg\[FILENAME].exe
    • %ProgramFiles%\comsoft\dialers\hotaction_sg\[FILENAME].exe
    • %ProgramFiles%\GMSoft\dialers\sexy_sg\sexy_sg.exe
    • %ProgramFiles%\SCom\dialers\hot_no\hot_no.exe
    • %ProgramFiles%\GMSoft\dialers\hot_it\hot_it.exe
    • %ProgramFiles%\GMSoft\dialers\horny_de\horny_de.exe
    • %ProgramFiles%\VCom\dialers\livesexcam_ca\livesexcam_ca.exe
    • %ProgramFiles%\VCom\dialers\sexcam_de\sexcams_de.exe
    • %ProgramFiles%\SCom\dialers\sexcams_br\sexcams_br.exe
    • %ProgramFiles%\gmsoft\dialers\easydates_it\easydates_it.exe
    • %System%\HotVideo_be-uninstall.exe
    • %System%\dialersetup\[FILENAME].exe
    • %System%\XXXNow_cn-uninstall.exe

      Note:
    • %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
    • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).
    • %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.

  4. May also drop the following clean components:

    • %Windir%\inf\vmplay.inf clean components
    • %System%\vmplay.dll
    • %Windir%\LastGood\vmplay.inf

  5. Adds the values:

    "Blonde_Tarts_ie" = "[EXECUTABLE PATH]"
    "Blondes" = "[EXECUTABLE PATH]"
    "EasyDates_it" = "[EXECUTABLE PATH]"
    "Gay_Sexy_fr" = "[EXECUTABLE PATH]"
    "Gay_Sexy_ie" = "[EXECUTABLE PATH]"
    "Gay_Sexy_it" = "[EXECUTABLE PATH]"
    "horny_de" = "[EXECUTABLE PATH]"
    "hot_it" = "[EXECUTABLE PATH]"
    "hot_no" = "[EXECUTABLE PATH]"
    "Hot_Tarts_de" = "[EXECUTABLE PATH]"
    "Hot_Tarts_fr" = "[EXECUTABLE PATH]"
    "Hot_Tarts_ie" = "[EXECUTABLE PATH]"
    "Hot_Tarts_il" = "[EXECUTABLE PATH]"
    "Hot_Tarts_pl" = "[EXECUTABLE PATH]"
    "Hot_Tarts_pt" = "[EXECUTABLE PATH]"
    "livesexcam_ca" = "[EXECUTABLE PATH]"
    "Playboy_fr" = "[EXECUTABLE PATH]"
    "sexcams_br" = "[EXECUTABLE PATH]"
    "sexcams_de" = "[EXECUTABLE PATH]"
    "Sexy_sg" = "[EXECUTABLE PATH]"
    "Sizzling_Blondes" = "[EXECUTABLE PATH]"
    "Virgins" = "[EXECUTABLE PATH]"
    "Virgins_ie" = "[EXECUTABLE PATH]"
    "xau" = "[EXECUTABLE PATH]"

    to the registry subkey:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

  6. Adds the values:

    "application/x-cnty" = "cnty"
    "application/x-cnty3" = "cnty3"
    "application/x-DTING" = "DTING"
    "application/x-fbba" = "fbba"
    "application/x-gmst" = "gmst"
    "application/x-gyst" = "gyst"
    "application/x-htnw" = "htnw"
    "application/x-mpmy" = "mpmy"
    "application/x-mpmy2" = "mpmy2"
    "application/x-pboy" = "pboy"
    "application/x-pmxy" = "pmxy"
    "application/x-pmxy2" = "[EXECUTABLE PATH]"
    "application/x-vmxn" = "vmxn"
    "application/x-vmxn" = "vmxn"
    "application/x-vmxy" = "vmxy"
    "application/x-vmxy" = "vmxy"
    "application/x-vmxy2" = "vmxy2"
    "application/x-vmxy3" = "vmxy3"


    to the registry subkey:

    HKEY_ALL_USERS\Software\Netscape\Netscape Navigator\Viewers

  7. Adds the value:

    "[EXECUTABLE PATH]" = ""

    to the registry subkey:

    HKEY_ALL_USERS\Software\Netscape\Netscape Navigator\User Trusted External Applications

  8. Adds the values:

    "application/x-cnty" = "cnty"
    "application/x-cnty3" = "cnty3"
    "application/x-DTING" = "DTING"
    "application/x-fbba" = "fbba"
    "application/x-gmst" = "gmst"
    "application/x-gyst" = "gyst"
    "application/x-htnw" = "htnw"
    "application/x-mpmy" = "mpmy"
    "application/x-mpmy2" = "mpmy2"
    "application/x-pboy" = "pboy"
    "application/x-pmxy" = "pmxy"
    "application/x-pmxy2" = "[EXECUTABLE PATH]"
    "application/x-vmxn" = "vmxn"
    "application/x-vmxy" = "vmxy"
    "application/x-vmxy2" = "vmxy2"
    "application/x-vmxy3" = "vmxy3"


    to the registry subkey:

    HKEY_ALL_USERS\Software\Netscape\Netscape Navigator\Suffixes

  9. Adds the values:

    "application/x-htnw" = "htnw"
    "application/x-htnw" = "htnw"

    to the registry subkey:

    HKEY_CLASSES_ROOT\MIME\Database\Content Type

  10. Adds the value:

    "Hot_Tarts_ie" = "[EXECUTABLE PATH]"

    to the registry subkey:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

  11. Adds the value:

    "UserInit" = "ATS7=75"

    to the registry subkeys:

    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{25DBCE51-6C8F-4A72-8A6D-B54C2B4FC835}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{36FC9E60-C465-11CF-8056-444553540000}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4658EE7E-F050-11D1-B6BD-00C04FA372A7}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{48721B56-6795-11D2-B1A8-0080C72E74A2}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{49CE6AC8-6F86-11D2-B1E5-0080C72E74A2}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E966-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96C-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96F-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E970-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E971-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E973-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E974-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E975-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E977-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E978-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E979-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E97D-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E97E-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{50127DC3-0F36-415E-A6CC-4CB3BE910B65}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{50906CB8-BA12-11D1-BF5D-0000F805F530}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{50DD5230-BA8A-11D1-BF5D-0000F805F530}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{533C5B84-EC70-11D2-9505-00C04F79DEAF}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{66F250D6-7801-4A64-B139-EEA80A450B24}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC5-810F-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC6-810F-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6D807884-7D21-11CF-801C-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{71A27CDD-812A-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{72631E54-78A4-11D0-BCF7-00AA00B7B32A}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{7EBEFBC0-3200-11D2-B4C2-00A0C9697D07}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{8ECC055D-047F-11D1-A537-0000F8753ED1}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{C06FF265-AE09-48F0-812C-16753D7CBA83}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{C459DF55-DB08-11D1-B009-00A0C9081FF6}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{CE5939AE-EBDE-11D0-B181-0000F8753EC4}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{D45B1C18-C8FA-11D1-9F77-0000F805F530}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{E0CBF06C-CD8B-4647-BB8A-263B43F0F974}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}

  12. May create one or more of the following registry keys:

    HKEY_CLASSES_ROOT\.vmxy2
    HKEY_CLASSES_ROOT\vmxy2 File
    HKEY_ALL_USERS\SOFTWARE\Mpb
    HKEY_ALL_USERS\SOFTWARE\MDevlst
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vmxn
    HKEY_LOCAL_MACHINE\SOFTWARE\Mpb
    HKEY_LOCAL_MACHINE\SOFTWARE\zlg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Blonde3_Tarts_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sizzling_Blondes_au
    HKEY_LOCAL_MACHINE\SOFTWARE\Video1
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{91433D86-9F27-402C-B5E3-DEBDD122C339}
    HKEY_ALL_USERS\Software\Video1
    HKEY_ALL_USERS\Software\zlg
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vmxy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application\x-vmxy
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-htnw
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-vmxy3
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-gyst
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-pboy
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-vmxn
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-vmxy
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-gmst
    HKEY_CLASSES_ROOT\.htnw
    HKEY_CLASSES_ROOT\.gyst
    HKEY_CLASSES_ROOT\.pboy
    HKEY_CLASSES_ROOT\.vmxn
    HKEY_CLASSES_ROOT\.vmxy3
    HKEY_CLASSES_ROOT\.vmxy
    HKEY_CLASSES_ROOT\.gmst
    HKEY_CLASSES_ROOT\htnw File
    HKEY_CLASSES_ROOT\vmxy3 File
    HKEY_CLASSES_ROOT\gyst File
    HKEY_CLASSES_ROOT\pboy File
    HKEY_CLASSES_ROOT\vmxn File
    HKEY_CLASSES_ROOT\vmxy File
    HKEY_CLASSES_ROOT\gmst File
    HKEY_CLASSES_ROOT\CLSID\{B5DD9A64-5C4B-4a48-BE56-97C1A8F85708}
    HKEY_CLASSES_ROOT\FastVideoPlayerLite.FastVideoPlayerLiteCtrl.1
    HKEY_CLASSES_ROOT\FastVideoPlayerLite.FastVideoPlayerLiteCtrl
    HKEY_CLASSES_ROOT\Interface\{9FF86C1B-7E6F-4A7F-932A-244FE7296DAE}
    HKEY_CLASSES_ROOT\Interface\{EE7E970D-3D17-4645-8660-D7F40B917092}
    HKEY_CLASSES_ROOT\TypeLib\{022850CB-74FD-486D-8B1C-573ECFD599AD}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Blonde_Tarts_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Blondes
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Lisa
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Virgins_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_au
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_es
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_fr
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_gb
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_no
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_pt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_se
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_de
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_ca
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_no
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_sg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_fr
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_pl
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_pt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_il
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Virgins
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_au
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_de
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_es
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_fr
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_no
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_pl
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_pt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_se
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sexy_Blondes
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sexy_Blondes_au
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\xau
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sizzling_Blondes
    HKEY_LOCAL_MACHINE\Software\MDevLst
    HKEY_LOCAL_MACHINE\Software\Pinfo
    HKEY_LOCAL_MACHINE\SOFTWARE\hbt
    HKEY_LOCAL_MACHINE\SOFTWARE\Playboy
    HKEY_LOCAL_MACHINE\SOFTWARE\sbl
    HKEY_LOCAL_MACHINE\SOFTWARE\sym
    HKEY_LOCAL_MACHINE\SOFTWARE\nog
    HKEY_LOCAL_MACHINE\SOFTWARE\SCom
    HKEY_ALL_USERS\Software\Pinfo
    HKEY_ALL_USERS\SOFTWARE\hbt
    HKEY_ALL_USERS\SOFTWARE\Playboy
    HKEY_ALL_USERS\SOFTWARE\Sbl
    HKEY_ALL_USERS\SOFTWARE\sym
    HKEY_ALL_USERS\SOFTWARE\nog
    HKEY_ALL_USERS\Software\SCom
    HKEY_ALL_USERS\Software\Program Info
    HKEY_ALL_USERS\Software\xau
    HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B5DD9A64-5C4B-4a48-BE56-97C1A8F85708}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-fbba
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.fbba
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fbba File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeBBAccess
    HKEY_ALL_USERS\Software\FBB
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\infxp
    HKEY_ALL_USERS\Software\INFXP
    HKEY_ALL_USERS\Software\ComSoft
    HKEY_ALL_USERS\Software\GMSoft
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.DTING
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DTING File
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-DTING
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-gmst
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.gmst
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gmst File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sexy_sg
    HKEY_LOCAL_MACHINE\SOFTWARE\GMSoft
    HKEY_ALL_USERS\SOFTWARE\gSoft
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-gmst2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.gmst2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gmst2 File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hot_no
    HKEY_ALL_USERS\SOFTWARE\SCom
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hot_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-cnty
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cnty
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cnty File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\horny_de
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-pmxy
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pmxy
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\pmxy File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\livesexcam_ca
    HKEY_LOCAL_MACHINE\SOFTWARE\VCom
    HKEY_ALL_USERS\SOFTWARE\VCom
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-pmxy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pmxy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\pmxy2 File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sexcams_br
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sexcams_de
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates_it
    HKEY_LOCAL_MACHINE\Software\Classes\MIME\Database\Content Type\application/x-dting
    HKEY_LOCAL_MACHINE\Software\Classes\dting File
    HKEY_LOCAL_MACHINE\Software\Classes\.dting
    HKEY_LOCAL_MACHINE\SOFTWARE\MDevLst
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-mpmy
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mpmy
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mpmy File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates_sg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HotAction_sg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sexy_br
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XXXmpeg
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-cnty3
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cnty3
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cnty3 File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DLuxde
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoGirls_fr
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WDInfo
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\xxxCam
    HKEY_LOCAL_MACHINE\SOFTWARE\GSoft
    HKEY_ALL_USERS\Software\wdinfo
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hotvideo_be
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dluxes
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates_dk
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_gb
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_br
    HKEY_ALL_USERS\Software\dluxes
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-mpmy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mpmy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mpmy2 File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\desired
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dlsp2mx
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\infwin
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_ca
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XXXmovie_be
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XXXNow_cn
    HKEY_ALL_USERS\Software\desired
    HKEY_ALL_USERS\Software\INFWIN
    HKEY_ALL_USERS\Software\SiteIcons
    HKEY_ALL_USERS\Software\Wmx
    HKEY_ALL_USERS\Software\NwRep
    HKEY_LOCAL_MACHINE\SOFTWARE\Wmx
    HKEY_LOCAL_MACHINE\SOFTWARE\Comsoft
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XXXmpegs
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\msevnt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates_pt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dluxcn
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_be
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_ve
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HotVideo_br
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_fr


  13. May add one or more of the following sections:

    • Blonde_Tarts_ie
    • Lisa
    • Virgins_ie
    • Blondes
    • Gay_sexy_it
    • Gay_sexy_pt
    • Gay_sexy
    • Hot_Tarts_pl
    • PlayBoy_it
    • PlayBoy_es
    • PlayBoy_de
    • PlayBoy_fr
    • PlayBoy_se
    • PlayBoy_au
    • PlayBoy_pt
    • PlayBoy_pl
    • PlayBoy_no
    • PlayBoy_ie
    • PlayBoy
    • Gay_Sexy_es
    • Gay_Sexy_de
    • Gay_Sexy_fr
    • Gay_Sexy_se
    • Gay_Sexy_au
    • Gay_Sexy_pl
    • Gay_Sexy_no
    • Gay_Sexy_ie
    • Sexy_Blondes
    • Sexy_Blondes_au
    • Sizzling_Blondes
    • Sizzling_Blondes_au
    • Hot_Tarts_fr
    • Hot_Tarts_pt
    • Hot_Tarts_de
    • Hot_Tarts_IE
    • EasyDates
    • EasyDates_it

      to the folder:

      %UserProfile%\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk

  14. May download additional software.


Search by name
Example: W32.Beagle.AG@mm
Windows 7
Windows Vista Security