Threat Explorer

The Threat Explorer is a comprehensive resource consumers can turn to for daily, accurate, up-to-date information on the latest threats, risks and vulnerabilities.

Dialer.Adultchat

Dialer.Adultchat

Updated:
13 February 2007
Risk Impact:
Low
Systems Affected:
Windows

Behavior


Dialer.Adultchat is a dialer program that can be used to access pornography, by dialling a high-cost telephone number using a modem.

Symptoms


Your Symantec program detects Dialer.Adultchat.
  • The modem unexpectedly dials long-distance phone numbers.

Behavior


The most common installation method of this dialer application is through various Web sites that are mainly pornographic in nature.

Antivirus Protection Dates

  • Initial Rapid Release version 02 October 2014 revision 022
  • Latest Rapid Release version 07 May 2019 revision 006
  • Initial Daily Certified version 09 October 2003 revision 003
  • Latest Daily Certified version 07 May 2019 revision 008
  • Initial Weekly Certified release date 15 October 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

When Dialer.AdultChat is executed, it performs the following actions:
  1. May display a message about its content, allowing a user to cancel or continue. If the user selects to continue, the dialer opens a Web page that displays terms and conditions. The page states the destination of the call, its charges, and content, as well as gives the user the option to cancel or continue.

  2. May drop shortcuts in the following locations:

    • %UserProfile%\Desktop
    • %UserProfile%\Start Menu
    • %UserProfile%\Start Menu\Programs
    • %SystemDrive%\Document and Settings\All Users\Desktop|

      Note:
    • %UserProfile% is a variable that refers to the current user's profile folder. By default, this is C:\Documents and Settings\[CURRENT USER] (Windows NT/2000/XP).
    • %SystemDrive% is a variable that refers to the drive on which Windows is installed. By default, this is drive C.

  3. May creates one or more of the following files:

    • %Windir%\Downloaded Program Files\games.inf
    • %Windir%\LastGood\Downloaded Program Files\games.inf
    • %System%\EasyDates_sg-uninstall.exe
    • %System%\HotAction_sg-uninstall.exe
    • %ProgramFiles%\pinfo\dialers\lisa\lisa.exe
    • %ProgramFiles%\nog\dialers\lisa\lisa.exe
    • %ProgramFiles%\hbt\dialers\blondes\blondes.exe
    • %ProgramFiles%\hbt\dialers\virgins_ie\[FILENAME].exe
    • %ProgramFiles%\scom\dialers\gay_sexy\[FILENAME].exe
    • %ProgramFiles%\scom\dialers\gay_sexy_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\hbt\dialers\hot_tarts_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\hbt\dialers\blonde_tarts_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\mpb\dialers\hot_tarts_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\playboy\dialers\playboy\[FILENAME].exe
    • %ProgramFiles%\playboy\dialers\playboy_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\sbl\dialers\sexy_blondes\[FILENAME].exe
    • %ProgramFiles%\sym\dialers\sexy_blondes_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\zlg\Dialers\Sizzling_Blondes_au\Sizzling_Blondes_au.exe
    • %ProgramFiles%\xau\xau\xau.exe
    • %System%\sndplay.dll
    • %ProgramFiles%\video1\dialers\hot_tarts_[COUNTRY]\[FILENAME].exe
    • %ProgramFiles%\fbb\freebbaccess\freebbaccess.exe
    • %ProgramFiles%\FreeBBAccess.lnk
    • %ProgramFiles%\infxp\infxp\infxp.exe
    • %ProgramFiles%\comsoft\dialers\easydates\[FILENAME].exe
    • %ProgramFiles%\comsoft\dialers\easydates_sg\[FILENAME].exe
    • %ProgramFiles%\comsoft\dialers\hotaction_sg\[FILENAME].exe
    • %ProgramFiles%\GMSoft\dialers\sexy_sg\sexy_sg.exe
    • %ProgramFiles%\SCom\dialers\hot_no\hot_no.exe
    • %ProgramFiles%\GMSoft\dialers\hot_it\hot_it.exe
    • %ProgramFiles%\GMSoft\dialers\horny_de\horny_de.exe
    • %ProgramFiles%\VCom\dialers\livesexcam_ca\livesexcam_ca.exe
    • %ProgramFiles%\VCom\dialers\sexcam_de\sexcams_de.exe
    • %ProgramFiles%\SCom\dialers\sexcams_br\sexcams_br.exe
    • %ProgramFiles%\gmsoft\dialers\easydates_it\easydates_it.exe
    • %System%\HotVideo_be-uninstall.exe
    • %System%\dialersetup\[FILENAME].exe
    • %System%\XXXNow_cn-uninstall.exe

      Note:
    • %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
    • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows (Windows 95/98/Me/XP) or C:\Winnt (Windows NT/2000).
    • %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.

  4. May also drop the following clean components:

    • %Windir%\inf\vmplay.inf clean components
    • %System%\vmplay.dll
    • %Windir%\LastGood\vmplay.inf

  5. Adds the values:

    "Blonde_Tarts_ie" = "[EXECUTABLE PATH]"
    "Blondes" = "[EXECUTABLE PATH]"
    "EasyDates_it" = "[EXECUTABLE PATH]"
    "Gay_Sexy_fr" = "[EXECUTABLE PATH]"
    "Gay_Sexy_ie" = "[EXECUTABLE PATH]"
    "Gay_Sexy_it" = "[EXECUTABLE PATH]"
    "horny_de" = "[EXECUTABLE PATH]"
    "hot_it" = "[EXECUTABLE PATH]"
    "hot_no" = "[EXECUTABLE PATH]"
    "Hot_Tarts_de" = "[EXECUTABLE PATH]"
    "Hot_Tarts_fr" = "[EXECUTABLE PATH]"
    "Hot_Tarts_ie" = "[EXECUTABLE PATH]"
    "Hot_Tarts_il" = "[EXECUTABLE PATH]"
    "Hot_Tarts_pl" = "[EXECUTABLE PATH]"
    "Hot_Tarts_pt" = "[EXECUTABLE PATH]"
    "livesexcam_ca" = "[EXECUTABLE PATH]"
    "Playboy_fr" = "[EXECUTABLE PATH]"
    "sexcams_br" = "[EXECUTABLE PATH]"
    "sexcams_de" = "[EXECUTABLE PATH]"
    "Sexy_sg" = "[EXECUTABLE PATH]"
    "Sizzling_Blondes" = "[EXECUTABLE PATH]"
    "Virgins" = "[EXECUTABLE PATH]"
    "Virgins_ie" = "[EXECUTABLE PATH]"
    "xau" = "[EXECUTABLE PATH]"

    to the registry subkey:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

  6. Adds the values:

    "application/x-cnty" = "cnty"
    "application/x-cnty3" = "cnty3"
    "application/x-DTING" = "DTING"
    "application/x-fbba" = "fbba"
    "application/x-gmst" = "gmst"
    "application/x-gyst" = "gyst"
    "application/x-htnw" = "htnw"
    "application/x-mpmy" = "mpmy"
    "application/x-mpmy2" = "mpmy2"
    "application/x-pboy" = "pboy"
    "application/x-pmxy" = "pmxy"
    "application/x-pmxy2" = "[EXECUTABLE PATH]"
    "application/x-vmxn" = "vmxn"
    "application/x-vmxn" = "vmxn"
    "application/x-vmxy" = "vmxy"
    "application/x-vmxy" = "vmxy"
    "application/x-vmxy2" = "vmxy2"
    "application/x-vmxy3" = "vmxy3"

    to the registry subkey:

    HKEY_ALL_USERS\Software\Netscape\Netscape Navigator\Viewers

  7. Adds the value:

    "[EXECUTABLE PATH]" = ""

    to the registry subkey:

    HKEY_ALL_USERS\Software\Netscape\Netscape Navigator\User Trusted External Applications

  8. Adds the values:

    "application/x-cnty" = "cnty"
    "application/x-cnty3" = "cnty3"
    "application/x-DTING" = "DTING"
    "application/x-fbba" = "fbba"
    "application/x-gmst" = "gmst"
    "application/x-gyst" = "gyst"
    "application/x-htnw" = "htnw"
    "application/x-mpmy" = "mpmy"
    "application/x-mpmy2" = "mpmy2"
    "application/x-pboy" = "pboy"
    "application/x-pmxy" = "pmxy"
    "application/x-pmxy2" = "[EXECUTABLE PATH]"
    "application/x-vmxn" = "vmxn"
    "application/x-vmxy" = "vmxy"
    "application/x-vmxy2" = "vmxy2"
    "application/x-vmxy3" = "vmxy3"

    to the registry subkey:

    HKEY_ALL_USERS\Software\Netscape\Netscape Navigator\Suffixes

  9. Adds the values:

    "application/x-htnw" = "htnw"
    "application/x-htnw" = "htnw"

    to the registry subkey:

    HKEY_CLASSES_ROOT\MIME\Database\Content Type

  10. Adds the value:

    "Hot_Tarts_ie" = "[EXECUTABLE PATH]"

    to the registry subkey:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

  11. Adds the value:

    "UserInit" = "ATS7=75"

    to the registry subkeys:

    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{25DBCE51-6C8F-4A72-8A6D-B54C2B4FC835}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{36FC9E60-C465-11CF-8056-444553540000}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4658EE7E-F050-11D1-B6BD-00C04FA372A7}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{48721B56-6795-11D2-B1A8-0080C72E74A2}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{49CE6AC8-6F86-11D2-B1E5-0080C72E74A2}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E966-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96C-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96F-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E970-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E971-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E973-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E974-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E975-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E977-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E978-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E979-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E97D-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E97E-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{50127DC3-0F36-415E-A6CC-4CB3BE910B65}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{50906CB8-BA12-11D1-BF5D-0000F805F530}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{50DD5230-BA8A-11D1-BF5D-0000F805F530}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{533C5B84-EC70-11D2-9505-00C04F79DEAF}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{66F250D6-7801-4A64-B139-EEA80A450B24}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC5-810F-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC6-810F-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6D807884-7D21-11CF-801C-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{71A27CDD-812A-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{72631E54-78A4-11D0-BCF7-00AA00B7B32A}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{7EBEFBC0-3200-11D2-B4C2-00A0C9697D07}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{8ECC055D-047F-11D1-A537-0000F8753ED1}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{C06FF265-AE09-48F0-812C-16753D7CBA83}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{C459DF55-DB08-11D1-B009-00A0C9081FF6}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{CE5939AE-EBDE-11D0-B181-0000F8753EC4}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{D45B1C18-C8FA-11D1-9F77-0000F805F530}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{E0CBF06C-CD8B-4647-BB8A-263B43F0F974}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}

  12. May create one or more of the following registry keys:

    HKEY_CLASSES_ROOT\.vmxy2
    HKEY_CLASSES_ROOT\vmxy2 File
    HKEY_ALL_USERS\SOFTWARE\Mpb
    HKEY_ALL_USERS\SOFTWARE\MDevlst
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vmxn
    HKEY_LOCAL_MACHINE\SOFTWARE\Mpb
    HKEY_LOCAL_MACHINE\SOFTWARE\zlg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Blonde3_Tarts_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sizzling_Blondes_au
    HKEY_LOCAL_MACHINE\SOFTWARE\Video1
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{91433D86-9F27-402C-B5E3-DEBDD122C339}
    HKEY_ALL_USERS\Software\Video1
    HKEY_ALL_USERS\Software\zlg
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vmxy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application\x-vmxy
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-htnw
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-vmxy3
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-gyst
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-pboy
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-vmxn
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-vmxy
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-gmst
    HKEY_CLASSES_ROOT\.htnw
    HKEY_CLASSES_ROOT\.gyst
    HKEY_CLASSES_ROOT\.pboy
    HKEY_CLASSES_ROOT\.vmxn
    HKEY_CLASSES_ROOT\.vmxy3
    HKEY_CLASSES_ROOT\.vmxy
    HKEY_CLASSES_ROOT\.gmst
    HKEY_CLASSES_ROOT\htnw File
    HKEY_CLASSES_ROOT\vmxy3 File
    HKEY_CLASSES_ROOT\gyst File
    HKEY_CLASSES_ROOT\pboy File
    HKEY_CLASSES_ROOT\vmxn File
    HKEY_CLASSES_ROOT\vmxy File
    HKEY_CLASSES_ROOT\gmst File
    HKEY_CLASSES_ROOT\CLSID\{B5DD9A64-5C4B-4a48-BE56-97C1A8F85708}
    HKEY_CLASSES_ROOT\FastVideoPlayerLite.FastVideoPlayerLiteCtrl.1
    HKEY_CLASSES_ROOT\FastVideoPlayerLite.FastVideoPlayerLiteCtrl
    HKEY_CLASSES_ROOT\Interface\{9FF86C1B-7E6F-4A7F-932A-244FE7296DAE}
    HKEY_CLASSES_ROOT\Interface\{EE7E970D-3D17-4645-8660-D7F40B917092}
    HKEY_CLASSES_ROOT\TypeLib\{022850CB-74FD-486D-8B1C-573ECFD599AD}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Blonde_Tarts_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Blondes
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Lisa
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Virgins_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_au
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_es
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_fr
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_gb
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_no
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_pt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_se
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_de
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_ca
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_no
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_sg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_fr
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_pl
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_pt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_il
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Virgins
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_au
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_de
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_es
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_fr
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_no
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_pl
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_pt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_se
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sexy_Blondes
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sexy_Blondes_au
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\xau
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sizzling_Blondes
    HKEY_LOCAL_MACHINE\Software\MDevLst
    HKEY_LOCAL_MACHINE\Software\Pinfo
    HKEY_LOCAL_MACHINE\SOFTWARE\hbt
    HKEY_LOCAL_MACHINE\SOFTWARE\Playboy
    HKEY_LOCAL_MACHINE\SOFTWARE\sbl
    HKEY_LOCAL_MACHINE\SOFTWARE\sym
    HKEY_LOCAL_MACHINE\SOFTWARE\nog
    HKEY_LOCAL_MACHINE\SOFTWARE\SCom
    HKEY_ALL_USERS\Software\Pinfo
    HKEY_ALL_USERS\SOFTWARE\hbt
    HKEY_ALL_USERS\SOFTWARE\Playboy
    HKEY_ALL_USERS\SOFTWARE\Sbl
    HKEY_ALL_USERS\SOFTWARE\sym
    HKEY_ALL_USERS\SOFTWARE\nog
    HKEY_ALL_USERS\Software\SCom
    HKEY_ALL_USERS\Software\Program Info
    HKEY_ALL_USERS\Software\xau
    HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B5DD9A64-5C4B-4a48-BE56-97C1A8F85708}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-fbba
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.fbba
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fbba File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeBBAccess
    HKEY_ALL_USERS\Software\FBB
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\infxp
    HKEY_ALL_USERS\Software\INFXP
    HKEY_ALL_USERS\Software\ComSoft
    HKEY_ALL_USERS\Software\GMSoft
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.DTING
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DTING File
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-DTING
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-gmst
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.gmst
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gmst File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sexy_sg
    HKEY_LOCAL_MACHINE\SOFTWARE\GMSoft
    HKEY_ALL_USERS\SOFTWARE\gSoft
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-gmst2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.gmst2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gmst2 File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hot_no
    HKEY_ALL_USERS\SOFTWARE\SCom
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hot_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-cnty
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cnty
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cnty File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\horny_de
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-pmxy
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pmxy
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\pmxy File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\livesexcam_ca
    HKEY_LOCAL_MACHINE\SOFTWARE\VCom
    HKEY_ALL_USERS\SOFTWARE\VCom
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-pmxy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pmxy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\pmxy2 File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sexcams_br
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sexcams_de
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates_it
    HKEY_LOCAL_MACHINE\Software\Classes\MIME\Database\Content Type\application/x-dting
    HKEY_LOCAL_MACHINE\Software\Classes\dting File
    HKEY_LOCAL_MACHINE\Software\Classes\.dting
    HKEY_LOCAL_MACHINE\SOFTWARE\MDevLst
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-mpmy
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mpmy
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mpmy File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates_sg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HotAction_sg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sexy_br
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XXXmpeg
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-cnty3
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cnty3
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cnty3 File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DLuxde
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoGirls_fr
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WDInfo
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\xxxCam
    HKEY_LOCAL_MACHINE\SOFTWARE\GSoft
    HKEY_ALL_USERS\Software\wdinfo
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hotvideo_be
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dluxes
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates_dk
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_gb
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_br
    HKEY_ALL_USERS\Software\dluxes
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-mpmy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mpmy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mpmy2 File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\desired
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dlsp2mx
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\infwin
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_ca
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XXXmovie_be
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XXXNow_cn
    HKEY_ALL_USERS\Software\desired
    HKEY_ALL_USERS\Software\INFWIN
    HKEY_ALL_USERS\Software\SiteIcons
    HKEY_ALL_USERS\Software\Wmx
    HKEY_ALL_USERS\Software\NwRep
    HKEY_LOCAL_MACHINE\SOFTWARE\Wmx
    HKEY_LOCAL_MACHINE\SOFTWARE\Comsoft
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XXXmpegs
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\msevnt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates_pt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dluxcn
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_be
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_ve
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HotVideo_br
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_fr

  13. May add one or more of the following sections:

    • Blonde_Tarts_ie
    • Lisa
    • Virgins_ie
    • Blondes
    • Gay_sexy_it
    • Gay_sexy_pt
    • Gay_sexy
    • Hot_Tarts_pl
    • PlayBoy_it
    • PlayBoy_es
    • PlayBoy_de
    • PlayBoy_fr
    • PlayBoy_se
    • PlayBoy_au
    • PlayBoy_pt
    • PlayBoy_pl
    • PlayBoy_no
    • PlayBoy_ie
    • PlayBoy
    • Gay_Sexy_es
    • Gay_Sexy_de
    • Gay_Sexy_fr
    • Gay_Sexy_se
    • Gay_Sexy_au
    • Gay_Sexy_pl
    • Gay_Sexy_no
    • Gay_Sexy_ie
    • Sexy_Blondes
    • Sexy_Blondes_au
    • Sizzling_Blondes
    • Sizzling_Blondes_au
    • Hot_Tarts_fr
    • Hot_Tarts_pt
    • Hot_Tarts_de
    • Hot_Tarts_IE
    • EasyDates
    • EasyDates_it

      to the folder:

      %UserProfile%\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\rasphone.pbk

  14. May download additional software.



The following instructions pertain to all Symantec antivirus products that support security risk detection.
  1. Update the definitions.
  2. Run a full system scan.
  3. Delete any values added to the registry.
For specific details on each of these steps, read the following instructions.

1. To update the definitions
To obtain the most recent definitions, start your Symantec program and run LiveUpdate.


2. To run the scan
  1. Start your Symantec antivirus program, and then run a full system scan.
  2. If any files are detected, and depending on which software version you are using, you may see one or more of the following options:

    Note: This applies only to versions of Norton AntiVirus that support security risk detection. If you are running a version of Symantec AntiVirus Corporate Edition that supports security risk detection, and security risk detection has been enabled, you will only see a message box that gives the results of the scan. If you have questions in this situation, contact your network administrator.
    • Exclude (Not recommended): If you click this button, it will set the risk so that it is no longer detectable. That is, the antivirus program will keep the security risk on your computer and will no longer detect it to remove from your computer.

    • Ignore or Skip: This option tells the scanner to ignore the risk for this scan only. It will be detected again the next time that you run a scan.

    • Cancel: This option is new to Norton Antivirus 2005. It is used when Norton Antivirus 2005 has determined that it cannot delete a security risk. This Cancel option tells the scanner to ignore the risk for this scan only, and thus, the risk will be detected again the next time that you run a scan.

      To actually delete the security risk:
      • Click its file name (under the Filename column).
      • In the Item Information box that displays, write down the full path and file name.
      • Then use Windows Explorer to locate and delete the file.

    • Delete: This option will attempt to delete the detected files. In some cases, the scanner will not be able to do this.
      • If you see a message, "Delete Failed" (or similar message), manually delete the file.
      • Click the file name of the risk that is under the Filename column.
      • In the Item Information box that displays, write down the full path and file name.
      • Then use Windows Explorer to locate and delete the file.

Important: If you are unable to start your Symantec antivirus product or the product reports that it cannot delete a detected file, you may need to stop the risk from running in order to remove it. To do this, run the scan in Safe mode. For instructions, read the document, How to start the computer in Safe Mode . Once you have restarted in Safe mode, run the scan again.

After the files are deleted, restart the computer in Normal mode and proceed with the next section.

Warning messages may be displayed when the computer is restarted, since the risk may not be fully removed at this point. You can ignore these messages and click OK. These messages will not appear when the computer is restarted after the removal instructions have been fully completed. The messages displayed may be similar to the following:

Title: [FILE PATH]
Message body: Windows cannot find [FILE NAME]. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search.

3. To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified subkeys only. Read the document: How to make a backup of the Windows registry .
  1. Click Start > Run.
  2. Type regedit

    Then click OK.

    Note: If the registry editor fails to open the risk may have modified the registry to prevent access to the registry editor. Security Response has developed a tool to resolve this problem. Download and run this tool, and then continue with the removal.

  3. Navigate to the subkey:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

  4. In the right pane, delete the values:

    "Blonde_Tarts_ie" = "[EXECUTABLE PATH]"
    "Blondes" = "[EXECUTABLE PATH]"
    "EasyDates_it" = "[EXECUTABLE PATH]"
    "Gay_Sexy_fr" = "[EXECUTABLE PATH]"
    "Gay_Sexy_ie" = "[EXECUTABLE PATH]"
    "Gay_Sexy_it" = "[EXECUTABLE PATH]"
    "horny_de" = "[EXECUTABLE PATH]"
    "hot_it" = "[EXECUTABLE PATH]"
    "hot_no" = "[EXECUTABLE PATH]"
    "Hot_Tarts_de" = "[EXECUTABLE PATH]"
    "Hot_Tarts_fr" = "[EXECUTABLE PATH]"
    "Hot_Tarts_ie" = "[EXECUTABLE PATH]"
    "Hot_Tarts_il" = "[EXECUTABLE PATH]"
    "Hot_Tarts_pl" = "[EXECUTABLE PATH]"
    "Hot_Tarts_pt" = "[EXECUTABLE PATH]"
    "livesexcam_ca" = "[EXECUTABLE PATH]"
    "Playboy_fr" = "[EXECUTABLE PATH]"
    "sexcams_br" = "[EXECUTABLE PATH]"
    "sexcams_de" = "[EXECUTABLE PATH]"
    "Sexy_sg" = "[EXECUTABLE PATH]"
    "Sizzling_Blondes" = "[EXECUTABLE PATH]"
    "Virgins" = "[EXECUTABLE PATH]"
    "Virgins_ie" = "[EXECUTABLE PATH]"
    "xau" = "[EXECUTABLE PATH]"

  5. Navigate to the subkey:

    HKEY_ALL_USERS\Software\Netscape\Netscape Navigator\Viewers

  6. In the right pane, delete the values:

    "application/x-cnty" = "cnty"
    "application/x-cnty3" = "cnty3"
    "application/x-DTING" = "DTING"
    "application/x-fbba" = "fbba"
    "application/x-gmst" = "gmst"
    "application/x-gyst" = "gyst"
    "application/x-htnw" = "htnw"
    "application/x-mpmy" = "mpmy"
    "application/x-mpmy2" = "mpmy2"
    "application/x-pboy" = "pboy"
    "application/x-pmxy" = "pmxy"
    "application/x-pmxy2" = "[EXECUTABLE PATH]"
    "application/x-vmxn" = "vmxn"
    "application/x-vmxn" = "vmxn"
    "application/x-vmxy" = "vmxy"
    "application/x-vmxy" = "vmxy"
    "application/x-vmxy2" = "vmxy2"
    "application/x-vmxy3" = "vmxy3"

  7. Navigate to the subkey:

    HKEY_ALL_USERS\Software\Netscape\Netscape Navigator\User Trusted External Applications

  8. In the right pane, delete the value:

    "[EXECUTABLE PATH]" = ""

  9. Navigate to the subkey:

    HKEY_ALL_USERS\Software\Netscape\Netscape Navigator\Suffixes

  10. In the right pane, delete the values:

    "application/x-cnty" = "cnty"
    "application/x-cnty3" = "cnty3"
    "application/x-DTING" = "DTING"
    "application/x-fbba" = "fbba"
    "application/x-gmst" = "gmst"
    "application/x-gyst" = "gyst"
    "application/x-htnw" = "htnw"
    "application/x-mpmy" = "mpmy"
    "application/x-mpmy2" = "mpmy2"
    "application/x-pboy" = "pboy"
    "application/x-pmxy" = "pmxy"
    "application/x-pmxy2" = "[EXECUTABLE PATH]"
    "application/x-vmxn" = "vmxn"
    "application/x-vmxy" = "vmxy"
    "application/x-vmxy2" = "vmxy2"
    "application/x-vmxy3" = "vmxy3"

  11. Navigate to the subkey:

    HKEY_CLASSES_ROOT\MIME\Database\Content Type

  12. In the right pane, delete the values:

    "application/x-htnw" = "htnw"
    "application/x-htnw" = "htnw"

  13. Navigate to the subkey:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

  14. In the right pane, delete the value:

    "Hot_Tarts_ie" = "[EXECUTABLE PATH]"

  15. Navigate to the subkeys:

    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Class\{4d36e96d-e325-11ce-bfc1-08002be10318}\0000
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{25DBCE51-6C8F-4A72-8A6D-B54C2B4FC835}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{36FC9E60-C465-11CF-8056-444553540000}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4658EE7E-F050-11D1-B6BD-00C04FA372A7}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{48721B56-6795-11D2-B1A8-0080C72E74A2}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{49CE6AC8-6F86-11D2-B1E5-0080C72E74A2}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E966-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96C-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96F-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E970-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E971-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E973-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E974-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E975-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E977-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E978-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E979-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E97D-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E97E-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{50127DC3-0F36-415E-A6CC-4CB3BE910B65}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{50906CB8-BA12-11D1-BF5D-0000F805F530}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{50DD5230-BA8A-11D1-BF5D-0000F805F530}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{533C5B84-EC70-11D2-9505-00C04F79DEAF}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{66F250D6-7801-4A64-B139-EEA80A450B24}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC5-810F-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC6-810F-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{6D807884-7D21-11CF-801C-08002BE10318}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{71A27CDD-812A-11D0-BEC7-08002BE2092F}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{72631E54-78A4-11D0-BCF7-00AA00B7B32A}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{7EBEFBC0-3200-11D2-B4C2-00A0C9697D07}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{8ECC055D-047F-11D1-A537-0000F8753ED1}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{A0A588A4-C46F-4B37-B7EA-C82FE89870C6}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{C06FF265-AE09-48F0-812C-16753D7CBA83}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{C459DF55-DB08-11D1-B009-00A0C9081FF6}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{CE5939AE-EBDE-11D0-B181-0000F8753EC4}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{D45B1C18-C8FA-11D1-9F77-0000F805F530}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{E0CBF06C-CD8B-4647-BB8A-263B43F0F974}
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}

  16. In the right pane, delete the value:

    "UserInit" = "ATS7=75"

  17. Navigate to and delete the following the subkeys:

    HKEY_CLASSES_ROOT\.vmxy2
    HKEY_CLASSES_ROOT\vmxy2 File
    HKEY_ALL_USERS\SOFTWARE\Mpb
    HKEY_ALL_USERS\SOFTWARE\MDevlst
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vmxn
    HKEY_LOCAL_MACHINE\SOFTWARE\Mpb
    HKEY_LOCAL_MACHINE\SOFTWARE\zlg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Blonde3_Tarts_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sizzling_Blondes_au
    HKEY_LOCAL_MACHINE\SOFTWARE\Video1
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{91433D86-9F27-402C-B5E3-DEBDD122C339}
    HKEY_ALL_USERS\Software\Video1
    HKEY_ALL_USERS\Software\zlg
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-vmxy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application\x-vmxy
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-htnw
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-vmxy3
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-gyst
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-pboy
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-vmxn
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-vmxy
    HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-gmst
    HKEY_CLASSES_ROOT\.htnw
    HKEY_CLASSES_ROOT\.gyst
    HKEY_CLASSES_ROOT\.pboy
    HKEY_CLASSES_ROOT\.vmxn
    HKEY_CLASSES_ROOT\.vmxy3
    HKEY_CLASSES_ROOT\.vmxy
    HKEY_CLASSES_ROOT\.gmst
    HKEY_CLASSES_ROOT\htnw File
    HKEY_CLASSES_ROOT\vmxy3 File
    HKEY_CLASSES_ROOT\gyst File
    HKEY_CLASSES_ROOT\pboy File
    HKEY_CLASSES_ROOT\vmxn File
    HKEY_CLASSES_ROOT\vmxy File
    HKEY_CLASSES_ROOT\gmst File
    HKEY_CLASSES_ROOT\CLSID\{B5DD9A64-5C4B-4a48-BE56-97C1A8F85708}
    HKEY_CLASSES_ROOT\FastVideoPlayerLite.FastVideoPlayerLiteCtrl.1
    HKEY_CLASSES_ROOT\FastVideoPlayerLite.FastVideoPlayerLiteCtrl
    HKEY_CLASSES_ROOT\Interface\{9FF86C1B-7E6F-4A7F-932A-244FE7296DAE}
    HKEY_CLASSES_ROOT\Interface\{EE7E970D-3D17-4645-8660-D7F40B917092}
    HKEY_CLASSES_ROOT\TypeLib\{022850CB-74FD-486D-8B1C-573ECFD599AD}
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Blonde_Tarts_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Blondes
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Lisa
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Virgins_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_au
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_es
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_fr
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_gb
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_no
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_pt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Gay_Sexy_se
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_de
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_ca
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_no
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_sg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_fr
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_pl
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_pt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_Tarts_il
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Virgins
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_au
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_de
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_es
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_fr
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_ie
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_no
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_pl
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_pt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Playboy_se
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sexy_Blondes
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sexy_Blondes_au
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\xau
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sizzling_Blondes
    HKEY_LOCAL_MACHINE\Software\MDevLst
    HKEY_LOCAL_MACHINE\Software\Pinfo
    HKEY_LOCAL_MACHINE\SOFTWARE\hbt
    HKEY_LOCAL_MACHINE\SOFTWARE\Playboy
    HKEY_LOCAL_MACHINE\SOFTWARE\sbl
    HKEY_LOCAL_MACHINE\SOFTWARE\sym
    HKEY_LOCAL_MACHINE\SOFTWARE\nog
    HKEY_LOCAL_MACHINE\SOFTWARE\SCom
    HKEY_ALL_USERS\Software\Pinfo
    HKEY_ALL_USERS\SOFTWARE\hbt
    HKEY_ALL_USERS\SOFTWARE\Playboy
    HKEY_ALL_USERS\SOFTWARE\Sbl
    HKEY_ALL_USERS\SOFTWARE\sym
    HKEY_ALL_USERS\SOFTWARE\nog
    HKEY_ALL_USERS\Software\SCom
    HKEY_ALL_USERS\Software\Program Info
    HKEY_ALL_USERS\Software\xau
    HKEY_ALL_USERS\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B5DD9A64-5C4B-4a48-BE56-97C1A8F85708}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-fbba
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.fbba
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\fbba File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FreeBBAccess
    HKEY_ALL_USERS\Software\FBB
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\infxp
    HKEY_ALL_USERS\Software\INFXP
    HKEY_ALL_USERS\Software\ComSoft
    HKEY_ALL_USERS\Software\GMSoft
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.DTING
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DTING File
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-DTING
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-gmst
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.gmst
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gmst File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sexy_sg
    HKEY_LOCAL_MACHINE\SOFTWARE\GMSoft
    HKEY_ALL_USERS\SOFTWARE\gSoft
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-gmst2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.gmst2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gmst2 File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hot_no
    HKEY_ALL_USERS\SOFTWARE\SCom
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hot_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-cnty
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cnty
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cnty File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\horny_de
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-pmxy
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pmxy
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\pmxy File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\livesexcam_ca
    HKEY_LOCAL_MACHINE\SOFTWARE\VCom
    HKEY_ALL_USERS\SOFTWARE\VCom
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-pmxy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pmxy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\pmxy2 File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sexcams_br
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sexcams_de
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates_it
    HKEY_LOCAL_MACHINE\Software\Classes\MIME\Database\Content Type\application/x-dting
    HKEY_LOCAL_MACHINE\Software\Classes\dting File
    HKEY_LOCAL_MACHINE\Software\Classes\.dting
    HKEY_LOCAL_MACHINE\SOFTWARE\MDevLst
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-mpmy
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mpmy
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mpmy File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates_sg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HotAction_sg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sexy_br
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XXXmpeg
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-cnty3
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cnty3
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\cnty3 File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DLuxde
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VideoGirls_fr
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WDInfo
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\xxxCam
    HKEY_LOCAL_MACHINE\SOFTWARE\GSoft
    HKEY_ALL_USERS\Software\wdinfo
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hotvideo_be
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dluxes
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates_dk
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_gb
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_br
    HKEY_ALL_USERS\Software\dluxes
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-mpmy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mpmy2
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mpmy2 File
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\desired
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\dlsp2mx
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\infwin
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_ca
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XXXmovie_be
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XXXNow_cn
    HKEY_ALL_USERS\Software\desired
    HKEY_ALL_USERS\Software\INFWIN
    HKEY_ALL_USERS\Software\SiteIcons
    HKEY_ALL_USERS\Software\Wmx
    HKEY_ALL_USERS\Software\NwRep
    HKEY_LOCAL_MACHINE\SOFTWARE\Wmx
    HKEY_LOCAL_MACHINE\SOFTWARE\Comsoft
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XXXmpegs
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\msevnt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyDates_pt
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Dluxcn
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hot_be
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_ve
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HotVideo_br
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_it
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\RoughRiders_fr
  18. Exit the Registry Editor.