![]() |
home  | what's new  | site map  | kudos  | links  | legal  | about |
| Advertising & Marketing  | Adware, Badware & Spyware  | Help & How To's |
|
This log was captured by Incntrl4 during a completed installation of MP3 TAG STUDIO (version 1.6.1) by Magnus Brading Software. A rejected installation of MP3 TAG STUDIO (hitting "I Do Not Agree" after reading the EULA) produced the same installation of Cydoor. This may or may not occur with other embedded software.
|
<-------------- Begin Report -------------->
Installation report: mp3ts161
(generated by INCTRL 4, version 1.1.0.0)
Install program: C:\Temp\MP3_Tag_Studio-v161\mp3ts161.exe
Saturday, June 24, 2000 06:27 PM
Windows 98
Notification by Real-time reporting
NO CHANGES MADE TO c:\windows\control.ini...
NO CHANGES MADE TO c:\windows\system.ini...
NO CHANGES MADE TO c:\windows\win.ini...
REGISTRY KEYS ADDED: (9)
---by process C:\WINDOWS\TEMP\ZEA10925\CD_LOAD.EXE
HKEY_CURRENT_USER\Software\Cydoor Services\Status\
HKEY_CURRENT_USER\Software\Cydoor\
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0
HKEY_CURRENT_USER\Software\Cydoor Services\Status\\cd_GIF
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1322
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1237
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1493
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1517
REGISTRY KEY VALUES ADDED: (102)
---by process C:\WINDOWS\TEMP\ZEA10925\CD_LOAD.EXE
HKEY_CURRENT_USER\Software\Cydoor\\ Desc2=@?OAC[????@
HKEY_CURRENT_USER\Software\Cydoor\\ UserCode=0
HKEY_CURRENT_USER\Software\Cydoor\\ TimeInter=30
HKEY_CURRENT_USER\Software\Cydoor\\ Desc=?????????
HKEY_CURRENT_USER\Software\Cydoor\\ Cms1Url=www.cms1.net
HKEY_CURRENT_USER\Software\Cydoor\\ Cms2Url=www.cms2.net
HKEY_CURRENT_USER\Software\Cydoor\\ Rgs1Url=www.rgs1.net
HKEY_CURRENT_USER\Software\Cydoor\\ Rgs2Url=www.rgs2.net
HKEY_CURRENT_USER\Software\Cydoor\\ Bns1Url=www.bns1.net
HKEY_CURRENT_USER\Software\Cydoor\\ Bns2Url=www.bns2.net
HKEY_CURRENT_USER\Software\Cydoor\\ AdsAddr=212.29.215.3:80
HKEY_CURRENT_USER\Software\Cydoor\\ TestUrl1=204.71.200.75
HKEY_CURRENT_USER\Software\Cydoor\\ TestUrl2=206.79.171.51
HKEY_CURRENT_USER\Software\Cydoor\\ TestUrl3=204.152.190.70
HKEY_CURRENT_USER\Software\Cydoor\\ TryNum=3
HKEY_CURRENT_USER\Software\Cydoor\\ SrvTryNum=2
HKEY_CURRENT_USER\Software\Cydoor\\ InitDelay=3
HKEY_CURRENT_USER\Software\Cydoor\\ AcceptDelay=10
HKEY_CURRENT_USER\Software\Cydoor\\ CheckDelay=10
HKEY_CURRENT_USER\Software\Cydoor\\ RasDelay=30
HKEY_CURRENT_USER\Software\Cydoor\\ ConnDelay=10
HKEY_CURRENT_USER\Software\Cydoor\\ SendDelay=10
HKEY_CURRENT_USER\Software\Cydoor\\ RecvDelay=10
HKEY_CURRENT_USER\Software\Cydoor\\ PauseDelay=0
HKEY_CURRENT_USER\Software\Cydoor\\ ShowDelay=10
HKEY_CURRENT_USER\Software\Cydoor\\ SleepDelay=10
HKEY_CURRENT_USER\Software\Cydoor\\ ConnTmout=30
HKEY_CURRENT_USER\Software\Cydoor\\ SendTmout=60
HKEY_CURRENT_USER\Software\Cydoor\\ RecvTmout=60
HKEY_CURRENT_USER\Software\Cydoor\\ ThrdGap=5
HKEY_CURRENT_USER\Software\Cydoor\\ ProbeGap=20
HKEY_CURRENT_USER\Software\Cydoor\\ MinLeftNum=0
HKEY_CURRENT_USER\Software\Cydoor\\ AdwrCnt=0
HKEY_CURRENT_USER\Software\Cydoor\\ LoctCnt=0
HKEY_CURRENT_USER\Software\Cydoor\\ SeqnCnt=0
HKEY_CURRENT_USER\Software\Cydoor\\ CacheConn=60
HKEY_CURRENT_USER\Software\Cydoor\\ ShowChange=1
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\ LoctNum=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\ Err=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\ MinLeftNum=10
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\ ConnFrqn=3
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\ SeqnCnt=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\ ClickNum=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\ DeftExpsLen=45
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\ DeftActvLen=10
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\ DeftNextLen=10
HKEY_CURRENT_USER\Software\Cydoor Services\Status\\cd_GIF\ Stt=0
HKEY_CURRENT_USER\Software\Cydoor\\ General0=?????????????????????????????????????????????????????O
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1322\ PrCode=7507
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1322\ ExpsCnt=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1322\ ExpsLast=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1322\ ExpsNum=2
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1322\ BannNum=1
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1322\ BannCnt=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1322\ FileTerm=GIF
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1322\ Url=http://click.linksynergy.com/fs-bin/stat?id=x1dzmSQ/7*g&offerid=8585.20&subid=0&type
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1322\ Conf=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1322\ ShowBann=1
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1322\ SeqnType=0
HKEY_CURRENT_USER\Software\Cydoor\Adwr_91\ SecCnt=961896334
HKEY_CURRENT_USER\Software\Cydoor\Adwr_91\ ValidKey=99068
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1237\ PrCode=9203
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1237\ ExpsCnt=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1237\ ExpsLast=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1237\ ExpsNum=2
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1237\ BannNum=1
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1237\ BannCnt=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1237\ FileTerm=GIF
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1237\ Url=http://click.linksynergy.com/fs-bin/stat?id=x1dzmSQ/7*g&offerid=14203.10000005&subid=0&type=4
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1237\ Conf=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1237\ ShowBann=1
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1237\ SeqnType=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1493\ PrCode=3503
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1493\ ExpsCnt=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1493\ ExpsLast=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1493\ ExpsNum=4
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1493\ BannNum=2
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1493\ BannCnt=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1493\ FileTerm=GIF
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1493\ Url=http://www.cydoor.com/Games
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1493\ Conf=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1493\ ShowBann=1
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1493\ SeqnType=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1517\ PrCode=3507
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1517\ ExpsCnt=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1517\ ExpsLast=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1517\ ExpsNum=4
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1517\ BannNum=2
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1517\ BannCnt=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1517\ FileTerm=GIF
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1517\ Url=http://www.cydoor.com/music
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1517\ Conf=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1517\ ShowBann=1
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\Loct_0\Seqn_1517\ SeqnType=0
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\ DistCode=0
HKEY_CURRENT_USER\Software\Cydoor Services\Status\\ bns_IdleState=0
HKEY_CURRENT_USER\Software\Cydoor Services\Status\\ bns_ErrCount=0
HKEY_CURRENT_USER\Software\Cydoor Services\Status\\ bns_TargetID=0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ Cydoor=CD_Load.exe
---by process C:\WINDOWS\TEMP\_INS0432._MP
REGISTRY KEY VALUES CHANGED: (10)
---by process C:\WINDOWS\TEMP\ZEA10925\CD_LOAD.EXE
HKEY_CURRENT_USER\Software\Cydoor\\ Desc2=@?OAC[????? (was @?OAC[????@)
HKEY_CURRENT_USER\Software\Cydoor\\Adwr_91\ LoctNum=1 (was 0)
HKEY_CURRENT_USER\Software\Cydoor\\ General0=???????????????????????????????????????G?????????????O (was ?????????????????????????????????????????????????????O)
HKEY_CURRENT_USER\Software\Cydoor\Adwr_91\ ValidKey=98000 (was 99068)
HKEY_CURRENT_USER\Software\Cydoor\\ General0=???????????????????????????????????????G?????????????O????????????????????????????A (was ???????????????????????????????????????G?????????????O)
HKEY_CURRENT_USER\Software\Cydoor\Adwr_91\ ValidKey=96194 (was 98000)
HKEY_CURRENT_USER\Software\Cydoor\\ General0=???????????????????????????????????????G?????????????O????????????????????????????A???A (was ???????????????????????????????????????G?????????????O????????????????????????????A)
HKEY_CURRENT_USER\Software\Cydoor\Adwr_91\ ValidKey=95278 (was 96194)
---by process C:\WINDOWS\TEMP\_INS0432._MP
FILES ADDED: (9)
---by process C:\WINDOWS\TEMP\ZEA10925\CD_LOAD.EXE
C:\WINDOWS\SYSTEM\CD_CLINT.DLL
C:\WINDOWS\SYSTEM\CD_GIF.DLL
C:\WINDOWS\SYSTEM\CD_LOAD.EXE
C:\WINDOWS\SYSTEM\ADCACHE\B_132200.GIF
C:\WINDOWS\SYSTEM\ADCACHE\B_123700.GIF
C:\WINDOWS\SYSTEM\ADCACHE\B_149300.GIF
C:\WINDOWS\SYSTEM\ADCACHE\B_149301.GIF
C:\WINDOWS\SYSTEM\ADCACHE\B_151700.GIF
C:\WINDOWS\SYSTEM\ADCACHE\B_151701.GIF
FILES DELETED: (0)
DIRECTORIES ADDED: (2)
---by process C:\WINDOWS\TEMP\ZEA10925\CD_LOAD.EXE
C:\WINDOWS\SYSTEM\ADCACHE
C:\WINDOWS\SYSTEM\ADCACHE\TEMP
DIRECTORIES DELETED: (3)
---by process C:\WINDOWS\TEMP\_INS0432._MP
C:\WINDOWS\TEMP\_ISTMP0.DIR
---by process C:\TEMP\MP3_TAG_STUDIO-V161\MP3TS161.EXE
C:\WINDOWS\TEMP\ZEA10925\ADVERCK
C:\WINDOWS\TEMP\ZEA10925
Exited the Cydoor app by closing icon in system tray and uninstalled MP3
Left in registry:
HKEY_CURRENT_USER\Software\Cydoor\
HKEY_CURRENT_USER\Software\Cydoor Services\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ Cydoor=CD_Load.exe
Left in C:\WINDOWS\SYSTEM\
CD_CLINT.DLL
CD_GIF.DLL
CD_LOAD.EXE
and
ADCACHE folder & contents:
B_132200.GIF
B_123700.GIF
B_149300.GIF
B_149301.GIF
B_151700.GIF
B_151701.GIF
HKEY_LOCAL_MACHINE\Software\Magnus Brading\Mp3/Tag Studio 1.61\1.61\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mp3/Tag Studio 1.61
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\mp3tag_s.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mp3/Tag Studio 1.61\ UninstallString=C:\WINDOWS\uninst.exe -f"C:\Program Files\Magnus Brading\Mp3-Tag Studio 1.61\DeIsL1.isu"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mp3/Tag Studio 1.61\ DisplayName=Mp3/Tag Studio 1.61
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\mp3tag_s.exe\ Path=C:\Program Files\Magnus Brading\Mp3-Tag Studio 1.61
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Mp3/Tag Studio 1.61\ UninstallString=C:\WINDOWS\uninst.exe -f"C:\Program Files\Magnus Brading\Mp3-Tag Studio 1.61\DeIsL1.isu" -c"C:\Program Files\Magnus Brading\Mp3-Tag Studio 1.61\_ISREG32.DLL" (was C:\WINDOWS\uninst.exe -f"C:\Program Files\Magnus Brading\Mp3-Tag Studio 1.61\DeIsL1.isu")
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\mp3tag_s.exe\ @=C:\Program Files\Magnus Brading\Mp3-Tag Studio 1.61\mp3tag_s.exe (was )
FILES ADDED:
---by process C:\WINDOWS\TEMP\_INS0432._MP
C:\PROGRAM FILES\MAGNUS BRADING\MP3-TAG STUDIO 1.61\DEISL1.ISU
C:\PROGRAM FILES\MAGNUS BRADING\MP3-TAG STUDIO 1.61\MP3TAG_S.EXE
C:\PROGRAM FILES\MAGNUS BRADING\MP3-TAG STUDIO 1.61\README.TXT
C:\PROGRAM FILES\MAGNUS BRADING\MP3-TAG STUDIO 1.61\MP3TS.DAT
C:\PROGRAM FILES\MAGNUS BRADING\MP3-TAG STUDIO 1.61\MP3TS_AC.DAT
C:\PROGRAM FILES\MAGNUS BRADING\MP3-TAG STUDIO 1.61\_DEISREG.ISR
C:\PROGRAM FILES\MAGNUS BRADING\MP3-TAG STUDIO 1.61\_ISREG32.DLL
C:\WINDOWS\START MENU\PROGRAMS\MP3-TAG STUDIO\MP3-TAG STUDIO 1.61.LNK
DIRECTORIES ADDED:
---by process C:\WINDOWS\TEMP\_INS0432._MP
C:\PROGRAM FILES\MAGNUS BRADING
C:\PROGRAM FILES\MAGNUS BRADING\MP3-TAG STUDIO 1.61
C:\WINDOWS\START MENU\PROGRAMS\MP3-TAG STUDIO
DIRECTORIES DELETED: (3)
---by process C:\WINDOWS\TEMP\_INS0432._MP
C:\WINDOWS\TEMP\_ISTMP0.DIR
---by process C:\TEMP\MP3_TAG_STUDIO-V161\MP3TS161.EXE
C:\WINDOWS\TEMP\ZEA10925\ADVERCK
C:\WINDOWS\TEMP\ZEA10925
<-------------- End Report -------------->
With WebWasher activated, many links on these pages will not display. Please see About page for fix.
This site uses no cookies or other tracking methods, no scripts and no active content. It looks better in IE than in Netscape.
Please send comments, corrections, suggestions, & new info to privacypwr@yahoo.com.